CVE-2025-3518 Details
Description
It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functionality is disabled for at least one use case, the system nevertheless allows files to be uploaded through direct API requests. During the upload file, interception and allowed file type rules are still applied correctly. If file sharing is generally enabled, this issue is not of concern.
A vulnerability exists in Unblu Spark versions 8.12.1 and earlier, as well as in version 7 through 7.53.4, allowing users to upload files to a conversation even when the file upload feature is disabled. This issue arises because the system still accepts file uploads through direct API requests, despite interception and file type rules being correctly applied. The vulnerability is not a concern if file sharing is generally enabled.
Users can upgrade to Unblu Spark version 8.13.1 or version 7.54.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.unblu.com/en/docs/latest/security-bulletins/#UBL-2025-002 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| unblu spark | >= 7.0.1, < 7.54.1 >= 8.0.1, < 8.13.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | Initial Analysis | [email protected] |
| Apr 24, 2025 | CVE Modified | CISA-ADP |
| Apr 22, 2025 | New CVE Received | [email protected] |