WhoDB contains a path traversal caused by lack of validation when opening database files, letting unauthenticated attackers access arbitrary Sqlite3 databases on the host system, exploit requires attacker to manipulate database filename input.
id: CVE-2025-24786
info:
name: WhoDB < 0.45.0 - Path Traversal
author: basicbeny
severity: hi
...