CVE-2025-30169: Admin Authorized File Upload and Execute PHP
File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30169?
CVE-2025-30169 is rated as a critical vulnerability due to the potential for PHP script injection if administrator credentials are compromised.
How do I fix CVE-2025-30169?
To resolve CVE-2025-30169, ensure that ASPECT-Enterprise, NEXUS Series, and MATRIX Series are updated to versions beyond 3.08.03 and implement strict credential management practices.
What are the impacts of CVE-2025-30169?
The impacts of CVE-2025-30169 include unauthorized execution of malicious PHP scripts, which can lead to data breaches and system compromises.
Who is affected by CVE-2025-30169?
Users of ASPECT-Enterprise, NEXUS Series, and MATRIX Series versions up to 3.08.03 are affected by CVE-2025-30169.
What should I do if my credentials are compromised concerning CVE-2025-30169?
If your credentials are compromised in relation to CVE-2025-30169, immediately change your passwords, review security logs for unusual activity, and update your software to mitigate the risk.