A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulation of the argument path results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 23 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Docsys Project
Docsys Project docsys
Vendors & Products Docsys Project
Docsys Project docsys

Fri, 17 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Oct 2025 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulation of the argument path results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title RainyGao DocSys File Upload uploadDoc.do updateRealDoc path traversal
Weaknesses CWE-22
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-10-12T07:32:04.891Z

Updated: 2025-10-17T14:34:15.741Z

Reserved: 2025-10-11T13:51:10.924Z

Link: CVE-2025-11630

cve-icon Vulnrichment

Updated: 2025-10-17T14:34:06.779Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-12T08:15:38.980

Modified: 2025-10-17T15:15:37.683

Link: CVE-2025-11630

cve-icon Redhat

No data.