CVE-2025-25478
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 28, 2025
Updated: Mar 5, 2025
CWE ID 73
Summary
CVE-2025-25478 is a vulnerability affecting Syspass 3.2.x, which allows for the disclosure of sensitive information through improper handling of special characters in filenames during account file uploads. The web application's source code, including the database password, becomes exposed as a result. This issue poses a significant risk to systems utilizing Syspass, and it is crucial for users to update to a patched version to mitigate it.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.