Back to overview

CVE-2025-59793

CRITICAL Exploitation: PoC
9.9
CVSS 3.1
Description
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.

Metadata

CVE ID
CVE-2025-59793
State
PUBLISHED
Assigner
mitre
Reserved
2025-09-22 00:00 UTC
Published
2026-02-17 00:00 UTC
Last updated
2026-03-11 15:19 UTC
Primary CWE
CWE-35
CWE-35 Path Traversal: '.../...//'
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-35 adp CWE-35 Path Traversal: '.../...//'
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
9.4 CRITICAL 4.0 adp CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview