CVE-2025-54790: Files: Potential for SQL Injection through File Browse and List Operations
Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized data access. This is fixed in version 0.16.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54790?
CVE-2025-54790 has a medium severity due to the potential for unauthorized data access through backend SQL query exploitation.
How do I fix CVE-2025-54790?
To fix CVE-2025-54790, upgrade to Files version 0.16.10 or later, which includes the necessary security patches.
What versions are affected by CVE-2025-54790?
CVE-2025-54790 affects Files versions 0.16.9 and below.
What type of vulnerability is CVE-2025-54790?
CVE-2025-54790 is a vulnerability related to unauthorized data access through insufficient validation of backend SQL queries.
Is CVE-2025-54790 a critical vulnerability?
CVE-2025-54790 is classified as a medium severity vulnerability, not critical, but still poses a significant risk.