PatchSiren

cld378632668 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM cld378632668 CVE published 2026-01-05

CVE-2025-15449

A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the function delete of the file src/main/java/com/macro/mall/controller/MinioController.java. This manipulation of the argument objectName causes path traversal. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version det [truncated]

MEDIUM cld378632668 CVE published 2026-01-05

CVE-2025-15448

A vulnerability was found in JavaMall, impacting the Upload function in MinioController.java, allowing for unrestricted file uploads. The vulnerability can be exploited remotely. As JavaMall uses rolling releases for continuous delivery, specific version details for affected and updated releases are not available. This medium-severity vulnerability poses a risk to deployments, and defenders should verify [truncated]