PT-2025-22520 · Unknown · Matrix Series+2

Published

2025-05-22

·

Updated

2025-05-22

·

CVE-2025-30169

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASPECT-Enterprise versions through 3.08.03 NEXUS Series versions through 3.08.03 MATRIX Series versions through 3.08.03
Description The issue allows PHP script injection if session administrator credentials become compromised. This is related to file upload and execute vulnerabilities in ASPECT.
Recommendations For ASPECT-Enterprise versions through 3.08.03, restrict access to file upload functionality to minimize the risk of PHP script injection. For NEXUS Series versions through 3.08.03, consider disabling the file upload feature until a fix is available. For MATRIX Series versions through 3.08.03, avoid using compromised session administrator credentials to prevent exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-30169

Affected Products

Aspect-Enterprise
Matrix Series
Nexus Series