CVE-2025-35112
EUVD-2025-2784726.08.2025, 23:15
Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| atlassian | agiloft | 19 ≤ 𝑥 < 31 |
𝑥
= Vulnerable software versions