CVE-2025-34508

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
17/06/2025
Last modified:
04/11/2025

Description

A path traversal vulnerability exists in the file dropoff functionality <br /> of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host <br /> system, or cause a denial of service.