Path Traversal and Unrestricted File Upload Vulnerabilities in GTONE ChangeFlow
CVE-2025-11221

9.4CRITICAL

Key Information:

Vendor

Gtone

Vendor
CVE Published:
2 October 2025

What is CVE-2025-11221?

The GTONE ChangeFlow application is susceptible to a path traversal vulnerability, allowing attackers to bypass directory restrictions and access sensitive information. Additionally, the application lacks proper controls to prevent the upload of potentially dangerous file types, leading to further security risks. This issue affects all versions of ChangeFlow up to and including v9.0.1.1, leaving systems exposed to exploit attempts that could compromise data integrity and confidentiality.

Affected Version(s)

ChangeFlow All versions

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arang(유재욱, Jaewook You
.
CVE-2025-11221 : Path Traversal and Unrestricted File Upload Vulnerabilities in GTONE ChangeFlow