---
id: CVE-2025-1782
title: >-
  In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is
  not properly sanitized 

  before being used and can be misused to include an arbitrary file in the
   PHP code allowing an attacker to do anything as the web serv…
summary: >-
  In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is
  not properly sanitized 

  before being used and can be misused to include an arbitrary file in the
   PHP code allowing an attacker to do anything as the web serv…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2025-04-14'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1782'
references:
  - url: 'https://www.ifax.com/security/CVE-2025-1782.html'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00544
epssPercentile: 0.43231
ingestedAt: '2026-07-27T17:21:54.852Z'
---

## Overview

In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized 
before being used and can be misused to include an arbitrary file in the
 PHP code allowing an attacker to do anything as the web server user. 
This flaw requires the attacker to be authenticated with a valid user account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
