Path Traversal Vulnerability in lsfusion Platform by lsfusion
CVE-2025-13262
Key Information:
Badges
What is CVE-2025-13262?
A path traversal vulnerability exists in the lsfusion platform, specifically in the UploadFileRequestHandler function. This flaw affects all versions of the platform up to 6.1. By exploiting this vulnerability through manipulation of the 'sid' argument, an attacker can gain unauthorized access to file system paths, potentially allowing them to read sensitive files. This exploit is remotely executable and poses significant risks to affected systems, especially since it has been publicly disclosed.
Affected Version(s)
platform 6.0
platform 6.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
