{"id":"CVE-2025-0502","details":"Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.","modified":"2026-04-10T05:20:17.935790Z","published":"2025-01-15T18:15:24.650Z","references":[{"type":"ADVISORY","url":"https://craftercms.com/docs/current/security/advisory.html#cv-2025011501"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftercms/craftercms","events":[{"introduced":"4b8dbed8102e5450b229abb05431acf9d326ba61"},{"fixed":"a7ed85b1da6816d3c602e4f3471c4880189dc046"}],"database_specific":{"versions":[{"introduced":"4.1.0"},{"fixed":"4.1.6"}]}}],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"4.0.0"},{"fixed":"4.0.8"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0502.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}