CVE-2025-15066

6.2 MEDIUM
Published: December 29, 2025 Modified: December 29, 2025

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Missing Authorization vulnerability in Innorix WP allows Path Traversal.This issue affects Innorix WP from All versions If the "exam" directory exists under the directory where the product is installed (ex: innorix/exam)

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://www.gnit.co.kr/software/innorix_product.html
Source: 09832df1-09c1-45b4-8a85-16c601d30feb
https://www.innorix.com/
Source: 09832df1-09c1-45b4-8a85-16c601d30feb

2 reference(s) from NVD

Quick Stats

CVSS v3 Score
6.2 / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)