CVE-2025-11466: Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability
Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability.
The specific flaw exists within the DatabaseBackupBL class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of the service account. Was ZDI-CAN-27136.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11466?
CVE-2025-11466 has been classified with a specific severity level that indicates a directory traversal information disclosure potential.
How do I fix CVE-2025-11466?
To fix CVE-2025-11466, ensure that you apply the latest patches and updates provided by Allegra for DatabaseBackupBL.
What type of vulnerability is CVE-2025-11466?
CVE-2025-11466 is a directory traversal vulnerability that allows remote attackers to disclose sensitive information.
Is authentication required to exploit CVE-2025-11466?
Yes, exploitation of CVE-2025-11466 requires authentication to be able to access the vulnerable part of the software.
Which software is affected by CVE-2025-11466?
CVE-2025-11466 affects Allegra DatabaseBackupBL and potentially other products by Allegra, depending on their configuration.