File Access Vulnerability in SS1 by DOS Osaka
CVE-2025-52460
6.9MEDIUM
What is CVE-2025-52460?
A vulnerability exists in SS1 versions 16.0.0.10 and earlier, as well as Media version 16.0.0a and earlier, that allows unauthenticated remote attackers to access sensitive files and configuration data. This flaw can lead to unauthorized information disclosure, exposing critical configuration files and uploaded documents to external entities.
Affected Version(s)
SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)
SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved