WeiPHP 5.0 contains a path traversal caused by insufficient input validation of the picUrl parameter in /public/index.php/material/Material/_download_imgage, letting unauthenticated remote attackers read arbitrary files.
id: CVE-2025-34045
info:
name: WeiPHP 5.0 - Path Traversal
author: pikpikcu
severity: high
...