An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Apr 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kovai
Kovai biztalk360 |
|
| CPEs | cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kovai
Kovai biztalk360 |
|
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Biztalk360
Biztalk360 biztalk360 |
|
| Vendors & Products |
Biztalk360
Biztalk360 biztalk360 |
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Allowing Super User File Read in Biztalk360 | |
| Weaknesses | CWE-22 |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-03T00:00:00.000Z
Updated: 2026-04-03T14:39:38.152Z
Reserved: 2025-09-19T00:00:00.000Z
Link: CVE-2025-59709
No data.
Status : Analyzed
Published: 2026-04-03T15:16:03.817
Modified: 2026-04-09T00:57:10.453
Link: CVE-2025-59709
No data.