VulnerabilityAnalyzed
CVE-2025-25478
This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
MEDIUM 6.5EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-73
- Affected
- syspass/syspass
- Source
- cve@mitre.org
References
- https://github.com/sysentr0py/CVEs/tree/main/CVE-2025-25478Exploit, Third Party Advisory
- https://github.com/sysentr0py/CVEs/tree/main/CVE-2025-25478Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.