Gin-vue-admin has an arbitrary file deletion vulnerability
Vulnerability Description
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66410
Credits & Attribution
No credits recorded in the NVD database.
References
More from flipped-aurora
View All →Affected Vendor
flipped-aurora
View all reports →