Data Exposure Vulnerability in Konsola Proget by Proget
CVE-2025-1421

2.4LOW

Key Information:

Vendor

Proget

Status
Vendor
CVE Published:
21 May 2025

What is CVE-2025-1421?

A vulnerability in Konsola Proget allows high privileged users to download sensitive data stored during the activation of new devices. This data, when accessed through a CSV file, can lead to potential remote access risks, especially if opened in applications like Microsoft Excel. Users may inadvertently compromise their systems, allowing attackers to gain unauthorized access.

Affected Version(s)

Proget 0 < 2.17.5

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcin Węgłowski (AFINE)
.