U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-27413

Change History

New CVE Received from GitHub, Inc. 2/28/2025 4:15:27 PM

Action Type Old Value New Value
Added Description

								
							
							
						
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an administrator to import raw data into the database, including Path Traversal (`../`) sequences. This is problematic for the template update functionality as it uses the path from the database to write arbitrary content to, potentially overwriting source code to achieve Remote Code Execution. Any user with the `backups:create`, `backups:update` and `templates:update` permissions (only administrators by default) can write arbitrary content to anywhere on the filesystem. By overwriting source code, it is possible to achieve Remote Code Execution. Version 1.2.0 fixes the issue.
Added CVSS V3.1

								
							
							
						
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Added CWE

								
							
							
						
CWE-22
Added Reference

								
							
							
						
https://github.com/pwndoc/pwndoc/blob/14acb704891245bf1703ce6296d62112e85aa995/backend/src/models/template.js#L170-L175
Added Reference

								
							
							
						
https://github.com/pwndoc/pwndoc/blob/14acb704891245bf1703ce6296d62112e85aa995/backend/src/routes/backup.js#L826-L827
Added Reference

								
							
							
						
https://github.com/pwndoc/pwndoc/blob/14acb704891245bf1703ce6296d62112e85aa995/backend/src/routes/template.js#L63-L66
Added Reference

								
							
							
						
https://github.com/pwndoc/pwndoc/commit/68aa1ea676a91e17bfb333a27571151bd07fb21d
Added Reference

								
							
							
						
https://github.com/pwndoc/pwndoc/releases/tag/v1.2.0
Added Reference

								
							
							
						
https://github.com/pwndoc/pwndoc/security/advisories/GHSA-r3vj-47cf-4672