CVE-2025-50325
MEDIUMBandiZip 7.37 - Unauthenticated Mark-of-the-Web Protection Bypass
Title source: llmDescription
BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip
Scores
CVSS v3
5.4
EPSS
0.0029
EPSS Percentile
20.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-693
Status
published
Published
Jul 22, 2026
Tracked Since
Jul 23, 2026