CVE-2025-43948

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 77

Summary

CVE-2025-43948 is a vulnerability affecting the KLIMS 1.6.DEV software from Codemers. This issue permits Python code injection, enabling attackers to execute arbitrary Python code on the server side. A user can exploit this vulnerability by providing Python code as an input value for certain parameters or qualifiers, such as those used for sorting. Successful exploitation could result in unauthorized access, data theft, or server compromise. Users are advised to patch their systems as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share