CVE-2025-26349
HIGHQ-free Maxtime < 2.11.0 - Path Traversal
Title source: ruleDescription
A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.
Scores
CVSS v3
7.2
EPSS
0.0148
EPSS Percentile
80.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-23
Status
published
Affected Products (1)
q-free/maxtime
< 2.11.0
Timeline
Published
Feb 12, 2025
Tracked Since
Feb 18, 2026