Unauthorized File Access in DbGate Database Manager
CVE-2025-50185
7HIGH
What is CVE-2025-50185?
DbGate, a cross-platform database management solution, is susceptible to unauthorized file access due to insufficient validation of file paths and types in versions 6.6.0 and earlier. This vulnerability permits users with application-level access to retrieve the contents of arbitrary files on the server, bypassing controls intended to restrict file access. The software lacks the necessary checks to validate the content type and file extension before securely reading a file. Consequently, sensitive files, including those typically protected by root user permissions, can be accessed through the application interface. Currently, there is no available fix for this vulnerability, leaving systems at risk.
Affected Version(s)
dbgate <= 6.6.0