CVE-2025-0422 - CVE House
Back to Database
Status published High CVE-2025-0422

Authenticated Remote Code Execution via ScriptVar

Vulnerability Description

An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the application. (Remote Code Execution) For this, the user must be able to create "ScriptVars" with the type „script" and preview them by, for example, creating a new "Info". By default, admin users have those permissions, but with the granular permission system, those permissions may be assigned to other users. An attacker is able to execute commands on the server running the "bestinformed Web" application if an account with the correct permissions was compromised before.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0422

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Manuel Kiesel (cyllective AG)
  • David Miller (cyllective AG)

Affected Vendor

Affected Software

bestinformed Web
Vulnerable Versions:
0, 6.2.2.5

Timeline

Official Publish: February 18th, 2025
Last Modified: February 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)