Local file inclusion vulnerability in LIVE CONTRACT
Vulnerability Description
A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitrary files, in the context of the application server, from the Linux server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2305
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Felix Schmid <felix.schmid@cirosec.de>
References
Affected Vendor
SYNCPILOT
View all reports →