Vulnerability Description
Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers are only those with a password-protected scan workflow connector. This issue affects Y Soft SafeQ 6 in versions before MU106.
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2026/01/CVE-2025-13175
- https://docs.ysoft.cloud/safeq6/latest/safeq6/release-notes-build-106
- https://www.ysoft.com/safeq
FAQ
What is CVE-2025-13175?
CVE-2025-13175 is a documented vulnerability. Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers a...
How severe is CVE-2025-13175?
CVSS scoring is not yet available for CVE-2025-13175. Check NVD for updates.
Is there a patch for CVE-2025-13175?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.