CVE-2025-43948

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.
Configurations

No configuration.

History

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) Codemers KLIMS 1.6.DEV permite la inyección de código Python. Un usuario puede proporcionar código Python como valor de entrada para un parámetro o calificador (por ejemplo, para ordenar), que se ejecutará en el servidor.

22 Apr 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-77

22 Apr 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 18:16

Updated : 2025-04-23 14:08


NVD link : CVE-2025-43948

Mitre link : CVE-2025-43948

CVE.ORG link : CVE-2025-43948


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')