logo

Warning: Path Traversal Vulnerability in ZendTo (CVE-2025-34508), Patch Immediately!

ID: dc20e608-b8dc-50d3-abb3-676ab9fff4c7

STIX ID: report--dc20e608-b8dc-50d3-abb3-676ab9fff4c7

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
60/100

Date Published: 2025-06-23

Date Updated: 2026-07-24

...
...

A path traversal vulnerability (CVE-2025-34508) affects ZendTo versions 6.15–7 and prior, allowing authenticated attackers to manipulate upload path parameters (chunkName, tmp_name) to access or tamper with files accessible to the web server; a public PoC exists and users are urged to upgrade to 6.15-8 and increase monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.