VYPR

Warehouse Management System

by Yeqifu

CVEs (2)

  • CVE-2025-65879HigDec 5, 2025
    risk 0.53cvss 8.1epss 0.01

    Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without…

  • CVE-2025-65878HigDec 5, 2025
    risk 0.49cvss 7.5epss 0.01

    The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitrary files on the server's file system.…