We’d love your feedback! Only 3 short questions and 5 min of your time. Take the short survey →

Security Advisories: CVE-2025-54347

A Directory Traversal vulnerability was found in the Application Server of Desktop Alert version 6.1.0.11 to 6.1.1.5 which allows an attacker to write arbitrary files under certain conditions.

Vulnerability Type(CWE-22) Directory Traversal 
CVE IdentifierCVE-2025-54347
CVSS Score9.9
CVSS Vector(CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
VendorDesktop Alert
Affected ProductPingAlert Application Server
Affected Versions6.1.0.11 – 6.1.1.5
AttackerAuthenticated user
ImpactArbitrary files could be uploaded
MitigationFixed in version 6.1.1.6

We would like to thank NATO Cyber Security Centre (NCSC) for their assistance in uncovering and addressing this vulnerability, in particular Roberto Suggi Liverani NCIA/NCSC and Justin Hocquel NCIA/NCSC.