External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://zuso.ai/advisory |
|
History
Fri, 21 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences. | |
| Title | Datiphy Data Management Center - External Control of File Name or Path | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2026-08-21T02:02:23.070Z
Reserved: 2026-08-19T08:03:53.871Z
Link: CVE-2026-76158
No data.
Status : Received
Published: 2026-08-21T03:16:39.903
Modified: 2026-08-21T03:16:39.903
Link: CVE-2026-76158
No data.
OpenCVE Enrichment
Updated: 2026-08-21T03:45:03Z
Weaknesses