Information Disclosure Vulnerability in Personal Management System by MorySummer
CVE-2025-29454

6.5MEDIUM

Key Information:

Vendor

MorySummer

Vendor
CVE Published:
17 April 2025

What is CVE-2025-29454?

A vulnerability exists in the Personal Management System version 1.4.65 that allows remote attackers to gain unauthorized access to sensitive information through its Upload function. This issue highlights the importance of implementing stringent input validation and security measures to prevent the exploitation of such flaws, ensuring user data remains protected.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.