PT-2025-49411 · Verysync · Verysync

Jjjjjzr

·

Published

2025-12-07

·

Updated

2025-12-07

·

CVE-2025-14198

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Verysync versions 2.21.3
Description A flaw exists in Verysync 微力同步 version 2.21.3 within the Web Administration Module. Manipulation of the /safebrowsing/clientreport/download?key=dummytoken file, through an unknown function, can lead to information disclosure. This issue is remotely exploitable, and the exploit is publicly available. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-14198

Affected Products

Verysync