Vulnerability Description
Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.
CVSS Score
HIGH
References
- https://partnersoftware.com/resources/software-release-info-4-32/
- https://kb.cert.org/vuls/id/317469
- https://www.kb.cert.org/vuls/id/317469
FAQ
What is CVE-2025-6076?
CVE-2025-6076 is a vulnerability with a CVSS score of 8.8 (HIGH). Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compr...
How severe is CVE-2025-6076?
CVE-2025-6076 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-6076?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.