CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-57794

CVSS 9.1v3.1pub. 2026-01-28upd. 2026-02-05

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remote code execution under default configurations.

🤖 AI Analysis
How it works

The application does not impose sufficient restrictions on file types uploaded through the administrative interface (CWE-434: Unrestricted Upload of File with Dangerous Type). An attacker with access to an administrator account can upload an executable file (e.g., webshell) to the server. The server then processes and executes the uploaded file, resulting in arbitrary code execution on the server side.

Impact

An attacker can gain full control over the server through remote code execution (RCE), which may lead to data breach, system integrity violation, and service availability loss. The attack scope extends beyond the application itself (Scope: Changed).

Mitigation & patch

Explorance Blue must be updated to version 8.14.9 or newer. Details available in the vendor's security bulletin from January 2026 (https://online-help.explorance.com/blue/articles/security-advisories-(january-2026)). Additionally, it is recommended to restrict access to the administrative interface only to trusted networks and apply the principle of least privilege.

Who is affected

Explorance Blue in versions prior to 8.14.9.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Explorance Blue

    APP
    Explorance
    < 8.14.9
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-57792CRITICAL10.0PL ✓same product

SQL Injection bez uwierzytelnienia w Explorance Blue (CVE-2025-57792)

CVE-2025-57795CRITICAL9.9PL ✓same product

RCE przez podatny upload plików w Explorance Blue (CVE-2025-57795)

CVE-2025-57793HIGH8.6same product

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validati...

CVE-2025-57796MEDIUM6.8same product

Explorance Blue w wersjach poprzedzających 8.14.12 stosuje odwracalne szyfrowanie symetryczne z zakodowanym st...

CVE-2025-52344MEDIUM6.1same product

Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers ...