CVE-2025-26349

HIGH

Q-free Maxtime < 2.11.0 - Path Traversal

Title source: rule

Description

A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.

Scores

CVSS v3 7.2
EPSS 0.0148
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-23
Status published

Affected Products (1)

q-free/maxtime < 2.11.0

Timeline

Published Feb 12, 2025
Tracked Since Feb 18, 2026