Vulnerability Description
PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cnblogs | Pdfpatcher | < 1.1.3.4663 |
Related Weaknesses (CWE)
References
- https://github.com/cydtseng/Vulnerability-Research/blob/main/pdfpatcher/DirectorExploitThird Party Advisory
- https://github.com/wmjordan/PDFPatcherProduct
- https://www.cnblogs.com/pdfpatcherProduct
FAQ
What is CVE-2025-63918?
CVE-2025-63918 is a vulnerability with a CVSS score of 6.2 (MEDIUM). PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.
How severe is CVE-2025-63918?
CVE-2025-63918 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63918?
Check the references section above for vendor advisories and patch information. Affected products include: Cnblogs Pdfpatcher.