CVE-2025-13261

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
References
Link Resource
https://github.com/lsfusion/platform/issues/1543 Exploit Issue Tracking Vendor Advisory
https://github.com/lsfusion/platform/issues/1543#issue-3576922131 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.332596 Permissions Required VDB Entry
https://vuldb.com/?id.332596 Third Party Advisory VDB Entry
https://vuldb.com/?submit.689412 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:lsfusion:lsfusion_platform:*:*:*:*:*:*:*:*

History

01 Dec 2025, 15:30

Type Values Removed Values Added
First Time Lsfusion lsfusion Platform
CPE cpe:2.3:a:lsfusion:platform:*:*:*:*:*:*:*:* cpe:2.3:a:lsfusion:lsfusion_platform:*:*:*:*:*:*:*:*

25 Nov 2025, 18:04

Type Values Removed Values Added
CPE cpe:2.3:a:lsfusion:platform:*:*:*:*:*:*:*:*
First Time Lsfusion
Lsfusion platform
References () https://github.com/lsfusion/platform/issues/1543 - () https://github.com/lsfusion/platform/issues/1543 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/lsfusion/platform/issues/1543#issue-3576922131 - () https://github.com/lsfusion/platform/issues/1543#issue-3576922131 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.332596 - () https://vuldb.com/?ctiid.332596 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.332596 - () https://vuldb.com/?id.332596 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.689412 - () https://vuldb.com/?submit.689412 - Third Party Advisory, VDB Entry

17 Nov 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-17 04:15

Updated : 2025-12-01 15:30


NVD link : CVE-2025-13261

Mitre link : CVE-2025-13261

CVE.ORG link : CVE-2025-13261


JSON object : View

Products Affected

lsfusion

  • lsfusion_platform
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')