PT-2026-20557 · Fileflows · Fileflows

Publicado

2026-02-18

·

Atualizado

2026-02-24

·

CVE-2025-15585

CVSS v4.0

7.6

Alta

VetorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Fileflows versions prior to 25.05.2
Description Fileflows is affected by an authenticated SQL injection issue in the library-file search function. Exploitation of this issue requires the system to utilize MySQL as the underlying database. Successful exploitation could lead to privilege escalation or data exfiltration.
Recommendations Update Fileflows to version 25.05.2 or later.

Correção

LPE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15585

Produtos afetados

Fileflows