CVE-2025-41428: Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON...

5.3 CVSS

Description

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the server may be viewed by a remote unauthenticated attacker.

Classification

CVE ID: CVE-2025-41428

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem Types

Improper limitation of a pathname to a restricted directory ('Path Traversal')

Affected Products

Vendor: Keiyo System Co., LTD

Product: TimeWorks

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 19.93% (scored less or equal to compared to others)

EPSS Date: 2025-06-08 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-41428
https://www.keiyo-system.co.jp/archives/11310
https://jvn.jp/en/jp/JVN37075430/

Timeline