Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is vulnerable to Path Traversal, which allows files to be written to arbitrary directories within the web root.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avepoint
Avepoint docave |
|
| Vendors & Products |
Avepoint
Avepoint docave |
Fri, 26 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Sep 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is vulnerable to Path Traversal, which allows files to be written to arbitrary directories within the web root. | |
| Title | Unrestricted uploading of dangerous file types to AvePoint products | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-09-26T09:51:12.104Z
Updated: 2025-09-26T12:41:19.401Z
Reserved: 2025-09-16T08:12:48.745Z
Link: CVE-2025-10544
Updated: 2025-09-26T12:18:21.278Z
Status : Awaiting Analysis
Published: 2025-09-26T10:15:44.673
Modified: 2025-09-26T14:32:19.853
Link: CVE-2025-10544
No data.