Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.
References
Configurations
No configuration.
History
04 Aug 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
02 Aug 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-02 03:15
Updated : 2025-08-04 15:06
NVD link : CVE-2025-6076
Mitre link : CVE-2025-6076
CVE.ORG link : CVE-2025-6076
JSON object : View
Products Affected
No product.
CWE
No CWE.