CVE-2025-59711
biztalk360
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal.
- CVSS
- 8.3
- EPSS
- 0.66% 47.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.04