Aller au contenu

Fiche vulnérabilité

CVE-2025-31134 : faille élevée freshrss freshrss (CVSS 7.5)

Description

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information about the server by checking if certain directories exist. An attacker can, for example, check if older PHP versions are installed or if certain software is installed on the server and potentially use that information to further attack the server. Version 1.26.2 contains a patch for the issue.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
4 juin 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • freshrss freshrss

Références

Rechercher une autre vulnérabilité dans la base CVE