Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.
CVE ID: CVE-2025-47423
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Vendor: pwsdashboard
Product: Personal Weather Station Dashboard
http/cves/2025/CVE-2025-47423.yaml
EPSS Score: 0.23% (probability of being exploited)
EPSS Percentile: 46.06% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)