VYPR

TRUfusion Enterprise

by TRUfusion

CVEs (3)

  • CVE-2025-27224CriOct 27, 2025
    risk 0.64cvss 9.8epss 0.01

    TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to write to any…

  • CVE-2025-27222HigOct 27, 2025
    risk 0.56cvss 8.6epss 0.02

    TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to read any…

  • CVE-2025-27223HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.02

    TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies…