Home

Description

Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.

PUBLISHED Reserved 2025-06-13 | Published 2025-08-02 | Updated 2025-11-03 | Assigner certcc

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

4.32 (custom) before 4.32.2
affected

References

kb.cert.org/vuls/id/317469

www.kb.cert.org/vuls/id/317469

partnersoftware.com/resources/software-release-info-4-32/

cve.org (CVE-2025-6076)

nvd.nist.gov (CVE-2025-6076)

Download JSON