Beveiligingsadvies

CVE-2025-1782

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-14 18:41:21
Laatst bijgewerkt 2026-07-27 16:43:41
Toegewezen door redhat
CVSS-score 9.9
Status PUBLISHED

Beschrijving

In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user account.