CVE-2025-26354
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
In short
An authenticated user can bypass file access restrictions in Q-Free MaxTime and overwrite important files by using specially crafted requests to the copy endpoint. This allows attackers with login access to damage or manipulate system files.
Technical detail
Path traversal vulnerability in the copy endpoint of maxtime/api/database/database.lua permits authenticated attackers to escape directory restrictions and overwrite arbitrary files. The vulnerability requires valid authentication credentials and allows file system manipulation through crafted HTTP requests, impacting confidentiality and integrity of protected resources.
Summary generated and translated by AI from the official description.
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Q-Free · MaxTime