Executive brief
Datiphy Data Management Center is a data management platform that provides file upload capabilities through an API endpoint. A vulnerability in the upload API allows attackers to write files to arbitrary locations on the server by using path traversal sequences, potentially enabling remote code execution or data corruption.
Technical details
The vulnerability is a path traversal (CWE-22) flaw in the upload API endpoint of Datiphy Data Management Center. The upload handler fails to properly validate or sanitize file path input, allowing attackers to use relative path sequences (e.g., "../") or absolute paths to write files outside the intended upload directory. The vulnerability is remotely exploitable without authentication requirements, affecting versions 8.3.0 through 8.5.1. An attacker can leverage this to overwrite critical files, inject malicious code, or corrupt application data.
Affected products
- Datiphy Data Management Center 8.3.0 through 8.5.1
Timeline
- 2026-08-21: disclosed