CVE Database
/

CVE-2025-54962

Back to search

CVE-2025-54962

Published: Aug 4, 2025

Modified: Aug 4, 2025

PUBLISHED

CVSS v3.1

6.4

MEDIUM

Description

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI.

VendorProductVersions

thiagoralves

OpenPLC_v3

affected
0 - <= 9cd8f1b53a50f9d38708096bfc72bcbb1ef47343

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now