CVE-2025-0731

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
26/02/2025
Last modified:
26/02/2025

Description

An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.

References to Advisories, Solutions, and Tools