PT-2026-21160 · Unknown · Vanquish Upload Files Anywhere
CVE-2025-69379
·
Publicado
2026-02-20
·
Atualizado
2026-02-22
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
vanquish Upload Files Anywhere versions prior to and including 2.8
Description
The software contains a flaw related to improper limitation of a pathname to a restricted directory, specifically a 'Path Traversal' issue. This impacts the Upload Files Anywhere component, allowing for potential unauthorized access or manipulation of files due to insufficient validation of file paths.
Recommendations
Update vanquish Upload Files Anywhere to a version newer than 2.8.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vanquish Upload Files Anywhere