File Upload Bypass in Unblu's Collaboration Platform
CVE-2025-3518
5.3MEDIUM
What is CVE-2025-3518?
A configuration flaw in Unblu's Collaboration Platform allows users to upload files via direct API requests even when the file upload functionality is disabled for specific use cases. This vulnerability presents a risk of unauthorized file uploads, as the system does not adequately enforce restrictions on file uploads during these API requests. Interception and file type validations remain intact during the upload process, potentially leading to security breaches if misused.
Affected Version(s)
Unblu Spark 7.0.0 <= 7.53.4
Unblu Spark 8.0.0 <= 8.12.1
Unblu Spark 7.54.1
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrei Dabrakou of Citadelo ([email protected])