PT-2025-47120 · Unknown · Lsfusion Platform

R1Ckyz

·

Published

2025-11-17

·

Updated

2025-12-01

·

CVE-2025-13265

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions lsfusion platform versions prior to 6.1
Description A flaw exists in the lsfusion platform that allows for path traversal. This issue is related to the unpackFile function located in the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. The manipulation of this function can lead to unauthorized access. This attack can be initiated remotely.
Recommendations Update to a version of lsfusion platform greater than 6.1. As a temporary workaround, consider restricting access to the unpackFile function until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-13265
GHSA-8WF8-FRJG-XV74

Affected Products

Lsfusion Platform