The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
History

Wed, 05 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Feb 2025 22:30:00 +0000

Type Values Removed Values Added
Description The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-05T15:33:21.373Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-25478

cve-icon Vulnrichment

Updated: 2025-03-05T15:33:15.595Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-28T23:15:11.170

Modified: 2025-03-05T16:15:39.297

Link: CVE-2025-25478

cve-icon Redhat

No data.