PT-2026-20557 · Fileflows · Fileflows
Publicado
2026-02-18
·
Atualizado
2026-02-24
·
CVE-2025-15585
CVSS v4.0
7.6
Alta
| Vetor | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Fileflows versions prior to 25.05.2
Description
Fileflows is affected by an authenticated SQL injection issue in the library-file search function. Exploitation of this issue requires the system to utilize MySQL as the underlying database. Successful exploitation could lead to privilege escalation or data exfiltration.
Recommendations
Update Fileflows to version 25.05.2 or later.
Correção
LPE
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fileflows