CVE-2025-55295 | StuffAnThings qbit_manage up to 4.5.3 restore_config_from_backup backup_id path traversal (GHSA-vh56-26wq-vvfv)
A vulnerability labeled as critical has been found in StuffAnThings qbit_manage up to 4.5.3. This affects an unknown part of the component restore_config_from_backup. The manipulation of the argument backup_id results in path traversal.
This vulnerability is reported as CVE-2025-55295. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.