CVE-2025-9060

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
15/08/2025
Last modified:
15/04/2026

Description

A vulnerability has been found in the  MSoft MFlash<br /> <br /> application that allows <br /> execution of arbitrary code on the server. The issue occurs in the <br /> integration configuration functionality that is only available to <br /> MFlash<br /> <br /> <br /> administrators. The vulnerability is related to insufficient validation<br /> of parameters when setting up security components.<br /> <br /> This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.