---
id: CVE-2025-13879
title: Directory traversal vulnerability in SOLIDserver IPAM v8.2.3
summary: >-
  Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This
  vulnerability allows an authenticated user with administrator privileges to
  list directories other than those to which the have authorized access using
  the 'directory' pa…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-22
vendor: efficientip
product: solidserver_ip_address_management
affected:
  - solidserver_ip_address_management = 8.2.3
published: '2025-12-02'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13879'
references:
  - url: 'https://efficientip.com/resources/solidserver-ipam-solutions-3/'
    label: cve-coordination@incibe.es
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/directory-traversal-vulnerability-efficientips-solidserver-ipam
    label: cve-coordination@incibe.es
tags:
  - nvd
epss: 0.00538
epssPercentile: 0.42914
ingestedAt: '2026-09-03T03:55:23.948Z'
---

## Overview

Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examplem setting the 'directory' parameter to '/' displays files outside the 'LOCAL:///' folder.

## Affected

- `solidserver_ip_address_management = 8.2.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
