CVE-2025-52460
MEDIUMDescription
Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exploited, uploaded files and SS1 configuration files may be accessed by a remote unauthenticated attacker.
Is your site exposed to CVE-2025-52460?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-52460? +
How severe is CVE-2025-52460? +
How do I check if I'm vulnerable to CVE-2025-52460? +
Related Vulnerabilities
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow …
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server …
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to …
Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a local file …
dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execution environments. In …
Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations …