CVE-2025-50184: DbGate allows for File Traversal via file parameter
DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the endpoint that lists files within the upload directory can be manipulated to access arbitrary files on the system. By supplying a crafted path to the file parameter, an attacker can read files outside the upload directory, potentially exposing sensitive system-level data. This is fixed in version 6.4.3-beta.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50184?
CVE-2025-50184 is categorized as a high severity vulnerability due to its potential for unauthorized file access via directory traversal.
How do I fix CVE-2025-50184?
To mitigate CVE-2025-50184, upgrade DbGate to version 6.4.3-premium-beta.6 or above, which resolves the directory traversal vulnerability.
What versions of DbGate are affected by CVE-2025-50184?
CVE-2025-50184 affects DbGate versions 6.4.3-premium-beta.5 and below.
What is the impact of CVE-2025-50184?
The impact of CVE-2025-50184 includes the potential for an attacker to list and access files outside the intended upload directory.
Is there a known exploit for CVE-2025-50184?
While a specific exploit for CVE-2025-50184 has not been publicly disclosed, the vulnerability itself poses a significant risk if not mitigated.