CVE-2025-7626 | YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd /onlinePreview url path traversal (Issue 13 / EUVD-2025-21363)
A vulnerability labeled as critical has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function onlinePreview of the file /onlinePreview. The manipulation of the argument url results in path traversal.
This vulnerability is identified as CVE-2025-7626. The attack can be executed remotely. Additionally, an exploit exists.
This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.