VulnAI


EUVD-2025-14362

ID: EUVD-2025-14362

Severity: critical

CVSS v4: Not provided

CVSS v3: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CWE: None listed

Source: ENISA

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

Timestamps

References

No references provided.