DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the endpoint that lists files within the upload directory can be manipulated to access arbitrary files on the system. By supplying a crafted path to the file parameter, an attacker can read files outside the upload directory, potentially exposing sensitive system-level data. This is fixed in version 6.4.3-beta.8.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 26 Jul 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the endpoint that lists files within the upload directory can be manipulated to access arbitrary files on the system. By supplying a crafted path to the file parameter, an attacker can read files outside the upload directory, potentially exposing sensitive system-level data. This is fixed in version 6.4.3-beta.8. | |
Title | DbGate allows for File Traversal via file parameter | |
Weaknesses | CWE-29 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-26T03:27:05.690Z
Updated: 2025-07-28T15:58:17.489Z
Reserved: 2025-06-13T19:17:51.726Z
Link: CVE-2025-50184

Updated: 2025-07-28T15:58:13.981Z

Status : Awaiting Analysis
Published: 2025-07-26T04:16:03.980
Modified: 2025-07-29T14:14:55.157
Link: CVE-2025-50184

No data.