An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and V5.*.*.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 03 Oct 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux
Markany
Markany safepc Enterprise
Microsoft
Microsoft windows
Vendors & Products Linux
Linux linux
Markany
Markany safepc Enterprise
Microsoft
Microsoft windows

Thu, 02 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Oct 2025 05:30:00 +0000

Type Values Removed Values Added
Description An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and V5.*.*.
Title Remote Code Execution in MarkAny SafePC Enterprise
Weaknesses CWE-22
CWE-434
CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: FSI

Published:

Updated: 2025-10-02T15:53:44.530Z

Reserved: 2025-09-26T07:16:13.357Z

Link: CVE-2025-11020

cve-icon Vulnrichment

Updated: 2025-10-02T15:29:02.696Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-02T06:15:34.177

Modified: 2025-10-02T19:11:46.753

Link: CVE-2025-11020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-03T08:22:53Z