before being used and can be misused to include an arbitrary file in the
PHP code allowing an attacker to do anything as the web server user.
This flaw requires the attacker to be authenticated with a valid user account.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10912 | Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| Link | Providers |
|---|---|
| https://www.ifax.com/security/CVE-2025-1782.html |
|
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Red Hat Product Security has come to the conclusion that this CVE is not needed. | In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user account. |
| Title | Unsanitized input in language form field | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Wed, 30 Apr 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Wed, 30 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsanitized input in language form field | |
| Metrics |
ssvc
|
Wed, 30 Apr 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user account. | Red Hat Product Security has come to the conclusion that this CVE is not needed. |
Mon, 14 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user account. | |
| Title | Unsanitized input in language form field | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-26T16:06:37.631Z
Reserved: 2025-02-28T15:49:58.508Z
Link: CVE-2025-1782
Updated: 2025-04-14T19:41:01.791Z
Status : Received
Published: 2025-04-14T19:15:36.277
Modified: 2026-05-26T17:16:28.547
Link: CVE-2025-1782
No data.
OpenCVE Enrichment
No data.
EUVD