CVE-2025-59710

An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-03 15:16

Updated : 2026-07-24 21:10


NVD link : CVE-2025-59710

Mitre link : CVE-2025-59710

CVE.ORG link : CVE-2025-59710


JSON object : View

Products Affected

kovai

  • biztalk360
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type