Luca Borzacchiello

9 exploits Active since Oct 2025
CVE-2025-58078 WRITEUP HIGH WRITEUP
Productivity Suite <4.4.1.19 - Path Traversal
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and write files with arbitrary data on the target machine.
CVSS 7.5
CVE-2025-58429 WRITEUP HIGH WRITEUP
Productivity Suite <4.4.1.19 - Path Traversal
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary files on the target machine.
CVSS 7.5
CVE-2025-58456 WRITEUP MEDIUM WRITEUP
Productivity Suite <4.4.1.19 - Path Traversal
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine.
CVSS 6.8
CVE-2025-59776 WRITEUP MEDIUM WRITEUP
Productivity Suite <4.4.1.19 - Path Traversal
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and create arbitrary directories on the target machine.
CVSS 4.0
CVE-2025-60023 WRITEUP MEDIUM WRITEUP
Productivity Suite <4.4.1.19 - Path Traversal
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary directories on the target machine.
CVSS 4.0
CVE-2025-61934 WRITEUP CRITICAL WRITEUP
Productivity Suite <v4.4.1.19 - SSRF
A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine
CVSS 10.0
CVE-2025-61977 WRITEUP HIGH WRITEUP
Productivity Suite <v4.4.1.19 - Info Disclosure
A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.
CVSS 7.0
CVE-2025-62498 WRITEUP HIGH WRITEUP
Productivity Suite <4.4.1.19 - Path Traversal
A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity project to execute arbitrary code on the machine where the project is opened.
CVSS 8.8
CVE-2025-62688 WRITEUP HIGH WRITEUP
Productivity Suite <4.4.1.19 - Privilege Escalation
An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project.
CVSS 7.1