CVE-2025-13262
Published
CVSS v3
7.3
HIGH
CVSS v2
7.5
HIGH
Affected
1
PROJECT
Description
A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. Executing manipulation of the argument sid can lead to path traversal. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
lsFusion is an extremely declarative open-source language-based platform for information systems development