Aller au contenu

Fiche vulnérabilité

CVE-2025-13261 : faille moyenne lsfusion lsfusion platform (CVSS 5.3)

Description

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
17 nov. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • lsfusion lsfusion platform

Références

Rechercher une autre vulnérabilité dans la base CVE