An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and V5.*.*.
History

Thu, 02 Oct 2025 05:30:00 +0000

Type Values Removed Values Added
Description An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and V5.*.*.
Title Remote Code Execution in MarkAny SafePC Enterprise
Weaknesses CWE-22
CWE-434
CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: FSI

Published:

Updated: 2025-10-02T05:15:50.859Z

Reserved: 2025-09-26T07:16:13.357Z

Link: CVE-2025-11020

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-02T06:15:34.177

Modified: 2025-10-02T06:15:34.177

Link: CVE-2025-11020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.