CVE-2025-6240
Description
Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authentication to the Profisee system.This issue affects Profisee: from 2020R1 before 2024R2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path traversal vulnerability in Profisee's File Attachment service allows authenticated attackers to read or modify arbitrary files on the server, affecting versions 2020R1 through 2024R2.
Vulnerability
Overview
The vulnerability resides in the File Attachment service of Profisee, where user-supplied input is not properly sanitized. This allows an attacker to inject directory traversal sequences (e.g., ../) to access files outside the intended directory structure [1]. The root cause is improper input validation in the filesystem modules on Windows.
Exploitation
Prerequisites
Exploitation requires valid Profisee credentials and a deep knowledge of the system. An attacker must already have compromised credentials and make targeted API calls to trigger the path traversal [1]. No authentication bypass is possible; the attacker must be authenticated to the Profisee system.
Impact
Successful exploitation could lead to unauthorized access to sensitive files, including configuration files or system files. Additionally, an attacker might modify configuration or system files, potentially compromising the system's integrity [1].
Mitigation
Profisee has developed a fix and is releasing hotfixes for all supported versions, as well as version 22R2 (which is out of support). For SaaS customers, the fix will be automatically deployed during the next maintenance window [1]. Customers hosting Profisee themselves can apply the hotfix manually.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.