An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2025-012 |
|
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Feb 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user. | |
| Title | SMA: Sunny Portal Remote Code Execution | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-02-26T10:01:50.336Z
Updated: 2025-02-26T15:27:59.319Z
Reserved: 2025-01-27T10:41:55.092Z
Link: CVE-2025-0731
Updated: 2025-02-26T14:50:12.144Z
Status : Received
Published: 2025-02-26T13:15:41.040
Modified: 2025-02-26T13:15:41.040
Link: CVE-2025-0731
No data.