Home

Description

On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.

PUBLISHED Reserved 2025-06-23 | Published 2025-06-23 | Updated 2025-06-23 | Assigner bizerba




CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-94 Improper Control of Generation of Code ('Code Injection')

Product status

Default status
affected

0.0 (semver) before 3.06
affected

Timeline

2025-06-22:Release of new Version BRAIN2 3.06

References

www.bizerba.com/...on-security/2025/bizerba-sa-2025-0004.pdf

cve.org (CVE-2025-6512)

nvd.nist.gov (CVE-2025-6512)

Download JSON