go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Jhenggao|iPublish System - Arbitrary File Reading through Path Traversal

TVN ID TVN-202507002
CVE ID CVE-2025-7146
CVSS 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products iPublish System
Description The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file.
Solution For school running the system on-premises, please contact the vendor to confirm the update status, or consider disabling external access and limiting use to within the campus only.
Credit JUI-PENG,YEN
Public Date 2025-07-07
Top