WhoDB < 0.45.0 - Path Traversal
CVE-2025-24786
Verified
Description
WhoDB contains a path traversal caused by lack of validation when opening database files, letting unauthenticated attackers access arbitrary Sqlite3 databases on the host system, exploit requires attacker to manipulate database filename input.
Severity
High
CVSS Score
7.5
Exploit Probability
3%
Affected Product
whodb
Published Date
February 1, 2026
Template Author
basicbeny
CVE-2025-24786.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-24786
CWE ID:
cwe-22
Remediation Steps
Upgrade to version 0.45.0 or later.