Path Traversal Vulnerability in GTONE ChangeFlow Affects Multiple Versions
CVE-2025-11182

7.1HIGH

Key Information:

Vendor

Gtone

Vendor
CVE Published:
2 October 2025

What is CVE-2025-11182?

The GTONE ChangeFlow application is susceptible to a Path Traversal vulnerability, allowing attackers to access restricted directories and execute arbitrary code. This issue impacts all ChangeFlow versions up to v9.0.1.1, posing significant risks to data integrity and security. Proper measures should be taken to mitigate the risk of unauthorized access through this flaw.

Affected Version(s)

ChangeFlow All versions

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arang(유재욱, Jaewook You)
.
CVE-2025-11182 : Path Traversal Vulnerability in GTONE ChangeFlow Affects Multiple Versions