← Back

CVE-2025-1782

nvd nist
Published: Apr 14, 2025Modified: Aug 6, 2026

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: secalert@redhat.com (Secondary)

Description

In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user account.

Affected (3)

Products: Avantfax: Avantfax · Ifax: Hylafax
1 product
Avantfax
1 product
Hylafax
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.4.1
Ifax
Before 1.2.1
From 1.3.0 to 1.3.2

References (1)

Source: secalert@redhat.com
MitigationVendor Advisory

Timeline

No history available yet.