Executive brief
Beyaz Computer CityPlus is a software solution used for municipal or urban management. A security vulnerability allows unauthorized individuals to bypass directory restrictions and access sensitive files on the server. This could lead to the exposure of confidential administrative data or system configuration files, potentially compromising the privacy of the organization's operations.
Technical details
A Path Traversal vulnerability (CWE-22) exists in Beyaz Computer CityPlus versions prior to 24.29375. The flaw stems from insufficient validation of user-supplied input used to construct file paths, allowing an attacker to use special sequences like '../' to escape the intended directory. This is a network-based attack that requires no authentication or user interaction. Successful exploitation allows a remote attacker to read arbitrary files on the filesystem, potentially leading to the disclosure of sensitive information. Users are advised to upgrade to version 24.29375 or later to mitigate this risk.
Affected products
- Beyaz Computer CityPlus before 24.29375
Timeline
- 2025-09-19: advisory: Initial publication of CVE-2025-10468