vendor:
Jasmin Ransomware
by:
bRpsd cy
7.1
CVSS
HIGH
Arbitrary File Download
89
CWE
Product Name: Jasmin Ransomware
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2025-XXXXX
CPE: a:codesiddhant:jasmin_ransomware
Platforms Tested: MacOS
2025
Jasmin Ransomware – (Authenticated) Arbitrary File Download
Jasmin Ransomware's web panel allows authenticated users to download arbitrary files due to a SQL Injection vulnerability, potentially leading to unauthorized access to sensitive data. This vulnerability has been assigned CVE-2025-XXXXX.
Mitigation:
To mitigate this vulnerability, ensure proper input validation and parameterized queries to prevent SQL Injection attacks. Additionally, restrict access to sensitive files based on user permissions.