It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functionality is disabled for at least one use case, the system nevertheless allows files to be uploaded through direct API requests. During the upload file, interception and allowed file type rules are still applied correctly. If file sharing is generally enabled, this issue is not of concern.
History

Thu, 24 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 22 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 09:00:00 +0000

Type Values Removed Values Added
Description It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functionality is disabled for at least one use case, the system nevertheless allows files to be uploaded through direct API requests. During the upload file, interception and allowed file type rules are still applied correctly. If file sharing is generally enabled, this issue is not of concern.
Title File upload functionality possible even when disabled
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published: 2025-04-22T08:49:56.073Z

Updated: 2025-04-24T14:59:31.675Z

Reserved: 2025-04-11T14:18:16.805Z

Link: CVE-2025-3518

cve-icon Vulnrichment

Updated: 2025-04-22T18:57:42.562Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-22T09:15:15.510

Modified: 2025-04-24T15:15:58.393

Link: CVE-2025-3518

cve-icon Redhat

No data.