Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.
History

Thu, 14 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 23:00:00 +0000

Type Values Removed Values Added
Description Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.
Title Part-DB Persistent Denial of Service via Uncaught Exception from Misleading File Extension in Avatar Upload
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-13T22:46:30.217Z

Updated: 2025-08-14T14:51:03.540Z

Reserved: 2025-08-08T21:55:07.963Z

Link: CVE-2025-55194

cve-icon Vulnrichment

Updated: 2025-08-14T13:41:59.829Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-13T23:15:27.327

Modified: 2025-08-14T15:15:41.260

Link: CVE-2025-55194

cve-icon Redhat

No data.