CVE-2025-59709
MEDIUMBizTalk360 <= 11.5 - Directory Traversal and Arbitrary File Read
Title source: manualDescription
An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.
References (1)
Core 1
Scores
CVSS v3
6.8
EPSS
0.0088
EPSS Percentile
54.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
kovai/biztalk360
< 11.6.3963.2611
Published
Apr 03, 2026
Tracked Since
Apr 03, 2026