No analysis available yet.
Vendor Solution
Update to the newest Version 3.06
Vendor Workaround
BRAIN2 users can be deprived of the right to edit the reports
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18870 | On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights. |
Mon, 23 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Jun 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights. | |
| Title | Scripts within reports executable on BRAIN2 Server | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: bizerba
Published:
Updated: 2025-06-23T13:22:47.485Z
Reserved: 2025-06-23T09:36:41.905Z
Link: CVE-2025-6512
Updated: 2025-06-23T13:22:43.966Z
Status : Awaiting Analysis
Published: 2025-06-23T13:15:22.460
Modified: 2025-06-23T20:16:21.633
Link: CVE-2025-6512
No data.
OpenCVE Enrichment
Updated: 2025-07-14T23:06:25Z
EUVD