Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
Any version before 1.1.*
affected
1.2.0 (semver) before 1.2.1
affected
1.3.0 (semver) before 1.3.2
affected
Default status
unaffected
Any version before 3.3.*
affected
3.4.0 (semver) before 3.4.1
affected
Description
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user account.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 1.1.*
1.2.0 (semver) before 1.2.1
1.3.0 (semver) before 1.3.2
Any version before 3.3.*
3.4.0 (semver) before 3.4.1
References
www.ifax.com/security/CVE-2025-1782.html