CVE-2025-59711 is a HIGH severity vulnerability in Biztalk360, a product of Kovai. This issue allows an authenticated attacker to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal. The vulnerability exists due to mishandling of user-provided input in an upload mechanism within Biztalk360. Affected product deployments should be identi [truncated]
CVE-2025-59710 is a remote code execution vulnerability in Biztalk360 before version 11.5. The issue arises from incorrect access control, allowing any user to request the loading of a DLL file. An attacker can exploit this vulnerability by crafting a malicious DLL, uploading it to the server, and using it to achieve remote code execution on the server. This vulnerability has a high CVSS score of 8.8. Org [truncated]