CVE-2020-25247: Hyland Onbase

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.

Affected products

  • Hyland Onbase: up to and including 18.0.0.32; from 19.0.0.0, up to and including 19.8.9.1000

Published 2020-09-11. Last modified 2026-06-17.