Path Traversal and SQL Injection Vulnerability in MarkAny SafePC Enterprise
CVE-2025-11020

8.7HIGH

Key Information:

Vendor

Markany

Vendor
CVE Published:
2 October 2025

What is CVE-2025-11020?

An attacker can exploit a Path Traversal vulnerability in MarkAny SafePC Enterprise, allowing unauthorized access to sensitive server information. This vulnerability may further lead to SQL Injection attacks, potentially leveraging an unrestricted file upload vulnerability. Affected versions include SafePC Enterprise V7.0.* prior to V7.0.1, as well as V5.. on both Windows and Linux systems.

Affected Version(s)

SafePC Enterprise Windows V7.0.* (V7.0.YYYY.MM.DD)

SafePC Enterprise Windows V5.*.*

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arang(유재욱, Jaewook You)
.
CVE-2025-11020 : Path Traversal and SQL Injection Vulnerability in MarkAny SafePC Enterprise