CVE-2025-56869
19.09.2025, 16:15
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.service.ts, and FilesManager.compress function in backend/src/applications/files/services/files-manager.service.ts.
| Vendor | Product | Version |
|---|---|---|
| sync-in | sync-in_server | 𝑥 ≤ 1.1.1 |
𝑥
= Vulnerable software versions