CVE-2025-34508: ZendTo < 6.15-8 Path Traversal
A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a denial of service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34508?
CVE-2025-34508 is considered a high-severity vulnerability due to its potential for unauthorized file access and denial of service.
How do I fix CVE-2025-34508?
To fix CVE-2025-34508, ensure that you upgrade to the latest version of ZendTo that is higher than 7.
What types of attacks can CVE-2025-34508 facilitate?
CVE-2025-34508 can facilitate remote file retrieval, unauthorized access to other users' files, and potential denial of service attacks.
Who is affected by CVE-2025-34508?
Users of ZendTo versions 6.15 through 7 are affected by CVE-2025-34508.
Is CVE-2025-34508 a remote vulnerability?
Yes, CVE-2025-34508 allows remote authenticated attackers to exploit the vulnerability.