CVE-2025-10245

medium

Description

A security flaw has been discovered in Display Painéis TGA up to 7.1.41. Affected by this issue is some unknown functionality of the file /gallery/rename of the component Galeria Page. The manipulation of the argument current_folder results in path traversal. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

References

https://vuldb.com/?submit.642068

https://vuldb.com/?id.323545

https://vuldb.com/?ctiid.323545

https://github.com/lfparizzi/CVE-TGA-7.1.41/tree/main

Details

Source: Mitre, NVD

Published: 2025-09-11

Updated: 2026-04-29

Risk Information

CVSS v2

Base Score: 4.7

Vector: CVSS2#AV:A/AC:L/Au:M/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 4.8

Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00024