PT-2026-21160 · Unknown · Vanquish Upload Files Anywhere

CVE-2025-69379

·

Publicado

2026-02-20

·

Atualizado

2026-02-22

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions vanquish Upload Files Anywhere versions prior to and including 2.8
Description The software contains a flaw related to improper limitation of a pathname to a restricted directory, specifically a 'Path Traversal' issue. This impacts the Upload Files Anywhere component, allowing for potential unauthorized access or manipulation of files due to insufficient validation of file paths.
Recommendations Update vanquish Upload Files Anywhere to a version newer than 2.8.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69379

Produtos afetados

Vanquish Upload Files Anywhere