Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.service.ts, and FilesManager.compress function in backend/src/applications/files/services/files-manager.service.ts.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 19 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 | |
Metrics |
cvssV3_1
|
Fri, 19 Sep 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.service.ts, and FilesManager.compress function in backend/src/applications/files/services/files-manager.service.ts. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-19T17:57:08.429Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56869

Updated: 2025-09-19T17:57:02.313Z

Status : Received
Published: 2025-09-19T16:15:45.953
Modified: 2025-09-19T18:15:36.787
Link: CVE-2025-56869

No data.

No data.