CVE-2025-25478

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 28, 2025
Updated: Mar 5, 2025
CWE ID 73

Summary

CVE-2025-25478 is a vulnerability affecting Syspass 3.2.x, which allows for the disclosure of sensitive information through improper handling of special characters in filenames during account file uploads. The web application's source code, including the database password, becomes exposed as a result. This issue poses a significant risk to systems utilizing Syspass, and it is crucial for users to update to a patched version to mitigate it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share