PT-2025-17583 · Labvantage · Labvantage

Nirmala Sriramulu

·

Published

2025-04-22

·

Updated

2025-04-24

·

CVE-2025-43951

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LabVantage versions prior to 8.8.0.13 HF6
Description The issue allows local file inclusion, enabling authenticated users to retrieve arbitrary files from the environment. This is achieved via the objectname request parameter.
Recommendations For versions prior to 8.8.0.13 HF6, update to version 8.8.0.13 HF6 or later to resolve the issue. As a temporary workaround, consider restricting access to the objectname request parameter to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-43951

Affected Products

Labvantage