Path Traversal and Unrestricted File Upload Vulnerabilities in GTONE ChangeFlow
CVE-2025-11221
9.4CRITICAL
What is CVE-2025-11221?
The GTONE ChangeFlow application is susceptible to a path traversal vulnerability, allowing attackers to bypass directory restrictions and access sensitive information. Additionally, the application lacks proper controls to prevent the upload of potentially dangerous file types, leading to further security risks. This issue affects all versions of ChangeFlow up to and including v9.0.1.1, leaving systems exposed to exploit attempts that could compromise data integrity and confidentiality.
Affected Version(s)
ChangeFlow All versions