PT-2025-17490 · Unblu · Unblu Spark+1

Andrei Dabrakou

·

Published

2025-04-22

·

Updated

2025-06-23

·

CVE-2025-3518

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description A user can upload a file to a conversation even if the file upload functionality is disabled. The system allows file uploads through direct API requests, despite the functionality being disabled for at least one use case. However, file interception and allowed file type rules are still applied correctly. This issue is not a concern if file sharing is generally enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2026-00061
CVE-2025-3518

Affected Products

Unblu Spark
Spark