---
id: CVE-2025-11631
title: A vulnerability was determined in RainyGao DocSys up to 2.02.36
summary: >-
  A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by
  this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do.
  Executing manipulation of the argument path can lead to path traversal. The
  attack…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-22
vendor: docsys_project
product: docsys
affected:
  - docsys <= 2.02.36
published: '2025-10-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11631'
references:
  - url: >-
      https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%88%A0%E9%99%A4.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.328043'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.328043'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664848'
    label: cna@vuldb.com
  - url: >-
      https://github.com/xkalami-Tta0/CVE/blob/main/DocSys/%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%88%A0%E9%99%A4.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00803
epssPercentile: 0.5535
ingestedAt: '2026-10-08T13:42:55.117Z'
---

## Overview

A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `docsys <= 2.02.36`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
