PT-2026-21160 · Unknown · Vanquish Upload Files Anywhere

Published

2026-02-20

·

Updated

2026-02-22

·

CVE-2025-69379

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions vanquish Upload Files Anywhere versions prior to and including 2.8
Description The software contains a flaw related to improper limitation of a pathname to a restricted directory, specifically a 'Path Traversal' issue. This impacts the Upload Files Anywhere component, allowing for potential unauthorized access or manipulation of files due to insufficient validation of file paths.
Recommendations Update vanquish Upload Files Anywhere to a version newer than 2.8.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-69379

Affected Products

Vanquish Upload Files Anywhere