Medium severity4.1NVD Advisory· Published Aug 26, 2025· Updated Apr 29, 2026
CVE-2025-35112
CVE-2025-35112
Description
Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-239-01.jsonnvdThird Party Advisory
- wiki.agiloft.com/display/HELP/What%27s+New%3A+CVE+ResolutionnvdRelease NotesVendor Advisory
- www.cve.org/CVERecordnvdThird Party Advisory
News mentions
0No linked articles in our index yet.