Junglewise Threat Intelligence

CVE-2025-10438: Yordam Katalog path traversal

CVE-2025-10438 · Severity: high · CVSS 8.6 · Published 2025-09-25

Executive brief

Yordam Katalog, a library cataloging and information management system, contains a security flaw that allows unauthorized access to internal files. An attacker can exploit this to view sensitive system data or configuration files that should be protected. This could lead to the exposure of confidential information or provide a foothold for further attacks on the organization's infrastructure.

Technical details

A path traversal vulnerability (CWE-27) exists in Yordam Katalog versions prior to 21.7. The flaw stems from insufficient sanitization of user-supplied input, specifically allowing 'dir/../../filename' sequences to escape the intended directory scope. A remote, unauthenticated attacker can exploit this over the network to read arbitrary files on the server. The vulnerability has been assigned a CVSS score of 8.6, reflecting high confidentiality impact and a network-based attack vector with no user interaction required. Users are advised to upgrade to version 21.7 or later to remediate the issue.

Affected products

  • Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog before 21.7

Timeline

  • 2025-09-25: advisory: Initial publication by TR-CERT/USOM
  • 2025-09-25: disclosed: CVE-2025-10438 published

References