Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.
References
Configurations
No configuration.
History
03 Nov 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
25 Sep 2025, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Aug 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
02 Aug 2025, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-02 03:15
Updated : 2025-11-03 20:19
NVD link : CVE-2025-6076
Mitre link : CVE-2025-6076
CVE.ORG link : CVE-2025-6076
JSON object : View
Products Affected
No product.
CWE
No CWE.
