CVE-2025-59711: Kovai BIZTALK360
High severity, CVSS 8.3. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal.
Affected products
- Kovai BIZTALK360: before 11.6.3963.2611 (fixed in 11.6.3963.2611)
Published 2026-04-03. Last modified 2026-07-24.