CVE-2025-13262

A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. Executing manipulation of the argument sid can lead to path traversal. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
References
Link Resource
https://github.com/lsfusion/platform/issues/1544 Exploit Issue Tracking Vendor Advisory
https://github.com/lsfusion/platform/issues/1544#issue-3589610731 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.332597 Permissions Required VDB Entry
https://vuldb.com/?id.332597 Third Party Advisory VDB Entry
https://vuldb.com/?submit.689414 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:lsfusion:platform:*:*:*:*:*:*:*:*

History

25 Nov 2025, 18:06

Type Values Removed Values Added
First Time Lsfusion
Lsfusion platform
CPE cpe:2.3:a:lsfusion:platform:*:*:*:*:*:*:*:*
References () https://github.com/lsfusion/platform/issues/1544 - () https://github.com/lsfusion/platform/issues/1544 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/lsfusion/platform/issues/1544#issue-3589610731 - () https://github.com/lsfusion/platform/issues/1544#issue-3589610731 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.332597 - () https://vuldb.com/?ctiid.332597 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.332597 - () https://vuldb.com/?id.332597 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.689414 - () https://vuldb.com/?submit.689414 - Third Party Advisory, VDB Entry

17 Nov 2025, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-17 05:16

Updated : 2025-11-25 18:06


NVD link : CVE-2025-13262

Mitre link : CVE-2025-13262

CVE.ORG link : CVE-2025-13262


JSON object : View

Products Affected

lsfusion

  • platform
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')