PT-2025-17580 · Codemers · Codemers Klims

Published

2025-04-22

·

Updated

2025-04-23

·

CVE-2025-43948

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Codemers KLIMS version 1.6.DEV
Description The issue allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier, such as for sorting, which will get executed on the server side.
Recommendations For Codemers KLIMS version 1.6.DEV, consider restricting the input values for parameters or qualifiers to prevent Python code injection until a patch is available. As a temporary workaround, restrict access to sensitive server-side functionality to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-43948

Affected Products

Codemers Klims