← Back to browse · API

CVE-2025-34508

Severity
MEDIUM
CVSS
5.3
EPSS
0.64856
Risk score
43.9
CISA KEV
No
PoC
No
Published
2025-06-17
Modified
2026-03-05
First seen
2026-08-07
Aliases
EUVD-2025-18507, GHSA-R6M3-WFX8-G4G7
Products
ZendTo:ZendTo 0 <6.15-8
Sources
euvd EUVD-2025-18507

Description

A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a denial of service.

References