CVE-2025-13261EPSS p51.9%
CVE-2025-13261CVE-2025-13261
lsfusion / lsfusion_platform
Description
A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.70% probability of exploitation · percentile 51.9% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |