Description

: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035.

INFO

Published Date :

2025-08-07T05:09:53.284Z

Last Modified :

2025-08-07T13:37:56.611Z

Source :

krcert
AFFECTED PRODUCTS

The following products are affected by CVE-2025-29866 vulnerability.

Vendors Products
Tagfree
  • X Free Uploader
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-29866.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability