Home
CRITICAL: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDefault status
affected
0.0 (semver) before 3.06
affected
Description
On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
0.0 (semver) before 3.06
Timeline
| 2025-06-22: | Release of new Version BRAIN2 3.06 |
References
www.bizerba.com/...on-security/2025/bizerba-sa-2025-0004.pdf