icon

We found results for “

CVE-2025-30673

Good to know:

icon

Date: March 31, 2025

Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution. Sub::HandlesVia uses Mite to produce the affected code section due to CVE-2025-30672

Severity Score

Severity Score

Weakness Type (CWE)

Uncontrolled Search Path Element

CWE-427

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/tobyink/p5-sub-handlesvia.git - 0.050002

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us