CVE-2025-2746
PUBLISHED
KEV
CVSS 9.300000190734863 CRITICAL
CVE-2025-2746:
A remote attacker without privileges can gain administrative privileges and control admin objects by exploiting the improper authentication in the password handling of empty SHA1 usernames in the Staging Sync Server.
CVE-2025-2747:
A remote attacker without privileges can gain administrative privileges and control admin objects by exploiting the improper authentication in the password handling for the type “None” as defined by the Staging Sync Server.
CVE-2025-2749:
A remote attacker with high privileges can upload arbitrary files to any location and execute path traversal by exploiting this improper limitation of a pathname to a restricted directory vulnerability. This can allow the attacker to execute code remotely on the server side, which can lead to complete system compromise.
EPSS 84.28% · 99.3th percentile