PT-2025-43987 · Unknown · Trufusion Enterprise
CVE-2025-27224
·
Publicado
2025-10-27
·
Atualizado
2025-10-27
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TRUfusion Enterprise versions through 7.10.4.0
Description
The application does not properly sanitize input to the
/trufusionPortal/fileupload endpoint, allowing path traversal sequences to be included. This can allow writing to any filename with any file type at any location on the local server, potentially leading to arbitrary code execution. The fileupload endpoint is vulnerable.Recommendations
Versions prior to 7.10.4.0 should be updated.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Trufusion Enterprise