On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.
Fixes

Solution

Update to the newest Version 3.06


Workaround

BRAIN2 users can be deprived of the right to edit the reports

History

Mon, 23 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.
Title Scripts within reports executable on BRAIN2 Server
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: bizerba

Published:

Updated: 2025-06-23T13:22:47.485Z

Reserved: 2025-06-23T09:36:41.905Z

Link: CVE-2025-6512

cve-icon Vulnrichment

Updated: 2025-06-23T13:22:43.966Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-23T13:15:22.460

Modified: 2025-06-23T20:16:21.633

Link: CVE-2025-6512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-14T23:06:25Z