S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated May 15, 2025

CVE-2025-1743 Scanner

CVE-2025-1743 Scanner - Arbitrary File Read vulnerability in Pichome

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-1743
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Pichomeby zyx0814
2.1.0
Updated Aug 22, 2026View on NVD →
Detail

Pichome is a software used primarily for managing and sharing images. Developed by zyx0814, it caters to individuals and organizations that need efficient image hosting solutions. Its interface includes features such as image categorization and permission controls for shared content. Users can access Pichome through a web interface, making it globally reachable online. The software often integrates into websites for seamless image retrieval and display. Known for its simplicity and ease of use, Pichome is popular among bloggers and small businesses.

The Arbitrary File Read vulnerability in question allows attackers to access unintended files on the server where Pichome is hosted. The path traversal issue arises because users can manipulate certain parameters in the URL to direct the application to read and expose sensitive files. This kind of vulnerability is critical because it can lead to unauthorized access to sensitive information. Attackers benefit from insufficient input validation, ultimately accessing server files that should otherwise be protected. Once exploited, it can serve as a launch point for deeper penetration into the network. It's crucial because the vulnerability can be exploited remotely without requiring authentication.

The vulnerability specifically targets an endpoint within Pichome: /index.php?mod=textviewer. By tampering with the 'src' parameter within the HTTP GET request, attackers manipulate it to initiate path traversal. This manipulation allows them to direct the application to read and return content from any readable file on the server. The issue with this endpoint is that it fails to validate or sanitize the input properly. As a result, attackers exploit this to craft URLs that extract data from critical files like /etc/passwd. Security researchers identified the vulnerability and disclosed that it might work against servers without appropriate security constraints.

If exploited, this vulnerability has the potential to expose sensitive server files, such as password hashes or system configurations. Attackers gaining access to files like /etc/passwd could subsequently attempt further exploitations like brute force attacks. Data theft, unauthorized information disclosure, and potential lateral movement within the network are possible consequences. Such vulnerabilities might lead to broader network compromises if supplemental checks and balances are not in place. System administrators and users could witness data integrity and confidentiality dilemmas. Hence, it requires immediate patching and mitigation to prevent malicious use.

REFERENCES

Solution Advice
  • Update to a version of Pichome that addresses the vulnerability.
  • Implement input validation and sanitize all user inputs to prevent path traversal.
  • Restrict access to sensitive files on the server level using proper permissions.
  • Employ web application firewalls (WAF) to block malicious requests targeting known vulnerabilities.
  • Regularly audit and monitor logs for unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.