CVE-2025-65878: Yeqifu Warehouse Management System
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitrary files on the server's file system. This could lead to the leakage of sensitive system information.
Affected products
- Yeqifu Warehouse Management System: version 1.2 only
Published 2025-12-05. Last modified 2026-09-25.