CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-1035: Path Traversal in Komtera Technolgies' KLog Server

5.7 CVSS

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

Classification

CVE ID: CVE-2025-1035

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.7

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

Vendor: Komtera Technolgies

Product: KLog Server

Nuclei Template

http/cves/2025/CVE-2025-1035.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 11.13% (probability of being exploited)

EPSS Percentile: 92.58% (scored less or equal to compared to others)

EPSS Date: 2025-03-19 (when was this score calculated)

References

https://www.usom.gov.tr/bildirim/tr-25-0037
https://www.klogserver.com/surum-notlari/3-1-1/

Timeline