CVE-2025-25478: Medium severity sysPass SysPass vulnerability
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25478?
CVE-2025-25478 is considered a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2025-25478?
To fix CVE-2025-25478, update Syspass to the latest version where this issue is resolved, or implement proper validation and sanitization of uploaded filenames.
What impact does CVE-2025-25478 have on my system?
CVE-2025-25478 can result in the disclosure of sensitive information, including the application’s source code and database credentials.
Is my Syspass version affected by CVE-2025-25478?
All Syspass versions from 3.2.0 are impacted by CVE-2025-25478 if they have the account file upload functionality enabled.
Who is the vendor responsible for CVE-2025-25478?
The vendor responsible for CVE-2025-25478 is Syspass.