CVE-2025-6076
Last modified
CVE-2025-6076 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6076?
How severe is CVE-2025-6076?
How do I fix CVE-2025-6076?
Are you affected by CVE-2025-6076?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
