CVE-2025-13261

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
References
Link Resource
https://github.com/lsfusion/platform/issues/1543 Exploit Issue Tracking Vendor Advisory
https://github.com/lsfusion/platform/issues/1543#issue-3576922131 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.332596 Permissions Required VDB Entry
https://vuldb.com/?id.332596 Third Party Advisory VDB Entry
https://vuldb.com/?submit.689412 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:lsfusion:lsfusion_platform:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-17 04:15

Updated : 2025-12-01 15:30


NVD link : CVE-2025-13261

Mitre link : CVE-2025-13261

CVE.ORG link : CVE-2025-13261


JSON object : View

Products Affected

lsfusion

  • lsfusion_platform
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')