It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled.
The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functionality is disabled for at least one use case, the system nevertheless allows files to be uploaded through direct API requests. During the upload file, interception and allowed file type rules are still applied correctly.
If file sharing is generally enabled, this issue is not of concern.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Tue, 22 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 22 Apr 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functionality is disabled for at least one use case, the system nevertheless allows files to be uploaded through direct API requests. During the upload file, interception and allowed file type rules are still applied correctly. If file sharing is generally enabled, this issue is not of concern. | |
Title | File upload functionality possible even when disabled | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: NCSC.ch
Published: 2025-04-22T08:49:56.073Z
Updated: 2025-04-24T14:59:31.675Z
Reserved: 2025-04-11T14:18:16.805Z
Link: CVE-2025-3518

Updated: 2025-04-22T18:57:42.562Z

Status : Awaiting Analysis
Published: 2025-04-22T09:15:15.510
Modified: 2025-04-24T15:15:58.393
Link: CVE-2025-3518

No data.