CVE-2025-6240 Details
Description
Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authentication to the Profisee system.This issue affects Profisee: from 2020R1 before 2024R2.
A path traversal vulnerability has been identified in the Profisee platform, specifically in versions 2020R1 prior to 2024R2. This vulnerability arises from improper input validation in the filesystem modules, allowing authenticated users to manipulate file paths and access files outside the intended directory structure. Successful exploitation requires valid Profisee credentials and knowledge of the system, targeting the File Attachment service via crafted API calls.
Profisee has developed a fix for this vulnerability, which will be included in the upcoming 25R0 release. Hotfixes are being back-ported for all supported versions, as well as 22R2 (out of support). Self-hosted customers can access the hotfix files through the Profisee support portal or via updated container images published to Profisee's container registry. For SaaS customers, the hotfix will be automatically deployed during the next maintenance window, with the option to request an earlier deployment.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2025CISA-ADP
Assessed Jun 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://profisee.com/security/vulnerabilities/detail/ | Profisee | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | Profisee |
Affected Products
| Product | Versions |
|---|---|
| Profisee | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Profisee |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jun 18, 2025 | New CVE Received | Profisee |
Volerion