CVE-2025-29454

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 17, 2025
Updated: Apr 22, 2025
CWE ID 918

Summary

CVE-2025-29454 is a newly disclosed vulnerability affecting the Personal Management System version 1.4.65. This issue grants remote attackers the ability to access sensitive information through the Upload function. By exploiting this vulnerability, an attacker can obtain data that is typically restricted to authorized users, potentially leading to privacy breaches or further unauthorized actions. The specific cause of the vulnerability has not been detailed, but affected users are urged to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share