Security Advisory

CVE-2025-25478

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-02-28 00:00:00
Last updated 2025-03-05 15:33:21
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.