Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8wf8-frjg-xv74 | lsFusion Server is vulnerable to Path Traversal through its unpackFile function |
Mon, 01 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lsfusion lsfusion Platform
|
|
| CPEs | cpe:2.3:a:lsfusion:lsfusion_platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lsfusion lsfusion Platform
|
Fri, 28 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lsfusion:platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Isfusion
Isfusion platform |
Tue, 25 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Isfusion
Isfusion platform |
|
| CPEs | cpe:2.3:a:isfusion:platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Isfusion
Isfusion platform |
Mon, 17 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lsfusion
Lsfusion platform |
|
| Vendors & Products |
Lsfusion
Lsfusion platform |
Mon, 17 Nov 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path traversal. It is possible to initiate the attack remotely. | |
| Title | lsfusion platform ZipUtils.java unpackFile path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-11-17T16:58:09.861Z
Reserved: 2025-11-16T15:33:22.440Z
Link: CVE-2025-13265
Updated: 2025-11-17T16:58:06.073Z
Status : Analyzed
Published: 2025-11-17T06:15:43.143
Modified: 2025-12-01T15:33:55.743
Link: CVE-2025-13265
No data.
OpenCVE Enrichment
Updated: 2025-11-17T10:09:17Z
Github GHSA