ZeroHour

CVE-2025-25478

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p37
Published
()
Modified
Description

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.

Vendors
syspass
Products
syspass
Weakness
CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.