• caglararli@hotmail.com
  • 05386281520

CVE-2025-26353 | Nozomi Q-Free MaxTime up to 2.11.0 HTTP maxtime/api/sql/sql.lua path traversal

Çağlar Arlı      -    5 Views

CVE-2025-26353 | Nozomi Q-Free MaxTime up to 2.11.0 HTTP maxtime/api/sql/sql.lua path traversal

A vulnerability, which was classified as problematic, has been found in Nozomi Q-Free MaxTime up to 2.11.0. This issue affects some unknown processing of the file maxtime/api/sql/sql.lua of the component HTTP Handler. The manipulation leads to path traversal: '.../...//'. The identification of this vulnerability is CVE-2025-26353. The attack may be initiated remotely. There is no exploit available.