CVE-2025-4546HIGH 8.8EPSS p40.6%
CVE-2025-4546CVE-2025-4546
Description
A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Knowledge Base Module. The manipulation leads to csv injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.10.8 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early about this disclosure.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.53% probability of exploitation · percentile 40.6% · 2026-06-19T12:03:05Z |
| Published | 2025-05-11 |
| Last modified | 2025-07-08 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Formula Elements in a CSV Filecwe-1236 | 0% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.