Q-Free MaxTime Relative Path Traversal Vulnerability in File Upload Mechanism

Vulnerability

A relative path traversal vulnerability has been identified in the file upload feature of Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to overwrite arbitrary files by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized file overwriting, potentially causing system compromise or a denial-of-service condition.

Remediation

No official patch is available from the vendor. However, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.8
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.