CVE-2025-9060
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
15/08/2025
Last modified:
15/04/2026
Description
A vulnerability has been found in the MSoft MFlash<br />
<br />
application that allows <br />
execution of arbitrary code on the server. The issue occurs in the <br />
integration configuration functionality that is only available to <br />
MFlash<br />
<br />
<br />
administrators. The vulnerability is related to insufficient validation<br />
of parameters when setting up security components.<br />
<br />
This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL



