216.73.217.80

CVE-2025-11020

· Published 02/10/2025 06:15 · Modified 02/10/2025 19:11

Labels: CVE-2025-11020 09832df1-09c1-45b4-8a85-16c601d30feb2025-10-02CVE-2025-11020CWE-22

Essential information

Published
02/10/2025 06:15
Modified
02/10/2025 19:11
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and V5.*.*.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
09832df1-09c1-45b4-8a85-16c601d30feb
NVD
View on NVD

Affected products (CPE)

ProductCPE
markany / safepc enterprise cpe:2.3:a:markany:safepc_enterprise:7.0.*:*:*:*:*:*:*:*
markany / safepc enterprise cpe:2.3:a:markany:safepc_enterprise:5.*.*:*:*:*:*:*:*:*

References