CVE-2025-41428
Severity CVSS v4.0:
MEDIUM
Type:
CWE-22
Path Traversal
Publication date:
03/06/2025
Last modified:
04/06/2025
Description
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the server may be viewed by a remote unauthenticated attacker.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM