CVE-2025-55194

Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:part-db_project:part-db:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-13 23:15

Updated : 2025-08-26 19:17


NVD link : CVE-2025-55194

Mitre link : CVE-2025-55194

CVE.ORG link : CVE-2025-55194


JSON object : View

Products Affected

part-db_project

  • part-db
CWE
CWE-248

Uncaught Exception