CVE-2025-3722: Path Traversal
A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files and exposing sensitive information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3722?
CVE-2025-3722 has a critical severity rating due to its potential for file system compromise.
How do I fix CVE-2025-3722?
To mitigate CVE-2025-3722, upgrade System Information Reporter to version 1.0.4 or later.
Who is affected by CVE-2025-3722?
CVE-2025-3722 affects System Information Reporter versions 1.0.3 and prior.
What type of vulnerability is CVE-2025-3722?
CVE-2025-3722 is a path traversal vulnerability that allows unauthorized file access.
What are the potential consequences of CVE-2025-3722?
The consequences of CVE-2025-3722 include unauthorized file creation and the risk of overwriting existing files.