A path traversal vulnerability in Vedo Suite 2024.17...
Moderate severity
Unreviewed
Published
Aug 6, 2025
to the GitHub Advisory Database
•
Updated Aug 6, 2025
Description
Published by the National Vulnerability Database
Aug 6, 2025
Published to the GitHub Advisory Database
Aug 6, 2025
Last updated
Aug 6, 2025
A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in '/api_vedo/template'.
References