Path Traversal and Unrestricted File Upload Vulnerabilities in GTONE ChangeFlow
CVE-2025-11221
9.4CRITICAL
What is CVE-2025-11221?
The GTONE ChangeFlow application is susceptible to a path traversal vulnerability, allowing attackers to bypass directory restrictions and access sensitive information. Additionally, the application lacks proper controls to prevent the upload of potentially dangerous file types, leading to further security risks. This issue affects all versions of ChangeFlow up to and including v9.0.1.1, leaving systems exposed to exploit attempts that could compromise data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ChangeFlow All versions
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
arang(유재욱, Jaewook You
