CVE-2025-11842

Published
View on NVD ↗
CVSS v3
6.3
MEDIUM
CVSS v2
6.5
MEDIUM
Affected
2
PROJECTS

Description

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The manipulation of the argument Version leads to path traversal. Remote exploitation of the attack is possible. Upgrading to version 4.6.0 is sufficient to resolve this issue. It is recommended to upgrade the affected component.

A lightweight runtime CSS/JavaScript file minification, combination, compression & management library for ASP.Net Core
GitHubGitHub
370
Vulnerability identified related to Smidge
GitHubGitHub