CVE-2025-11034: Dibo Data Decision Making System
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function downloadImpTemplet of the file /common/dep/common_dep.action.jsp. The manipulation of the argument filePath results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected products
- Dibo Data Decision Making System: version 2.0 only; version 2.1 only; version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only; …
Published 2025-09-26. Last modified 2026-10-09.