External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://zuso.ai/advisory |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-21 03:16
Updated : 2026-08-26 16:55
NVD link : CVE-2026-76158
Mitre link : CVE-2026-76158
CVE.ORG link : CVE-2026-76158
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
