CVE-2025-1421

LOW

Konsola Proget <2.17.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Data provided in a request performed to the server while activating a new device are put in a database. Other high privileged users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC. This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

Scores

CVSS v4 2.4
EPSS 0.0013
EPSS Percentile 31.4%
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1236
Status published
Products (1)
Proget/Proget < 2.17.5
Published May 21, 2025
Tracked Since Feb 18, 2026