CVE-2025-13262

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-13262
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13262.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13262
Aliases
Published
2025-11-17T05:16:04.427Z
Modified
2025-12-03T02:18:06.961913Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. Executing manipulation of the argument sid can lead to path traversal. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

References

Affected packages

Git / github.com/lsfusion/platform

Affected ranges

Type
GIT
Repo
https://github.com/lsfusion/platform
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

2.*

2.0
2.1
2.2
2.3
2.4

3.*

3.0
3.1
3.beta.0

4.*

4.0
4.0-beta0
4.0-beta1
4.0-beta2
4.0-beta3
4.1

5.*

5.0
5.0-beta0
5.1

6.*

6.0
6.0-beta0
6.0-beta1
6.0-beta2
6.1