# Y Soft SafeQ 6 密码存储漏洞
## 概述
Y Soft SafeQ 6 在版本 MU106 之前存在一个安全漏洞,管理员可通过浏览器开发者工具查看 Workflow Connector 中的密码明文。
## 影响版本
Y Soft SafeQ 6 版本早于 MU106。
## 细节
Workflow Connector 的密码字段在前端渲染时未正确保护,导致拥有 UI 访问权限的管理员可通过浏览器的开发工具或元素检查功能直接查看密码明文。
## 影响
仅使用密码保护的扫描工作流连接器的客户受影响。攻击者或恶意管理员可能利用此漏洞获取敏感凭证,进而访问受保护的扫描工作流系统。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: Vulnerability in Ysoft SafeQ 6 software | CERT Polska -- 🔗来源链接
标签:third-party-advisory
神龙速读:
## Vulnerability Summary
- **CVE ID**: CVE-2025-13175
- **Publication Date**: 14 January 2026
- **Vendor**: YSoft
- **Product**: SafeQ 6
- **Vulnerable Versions**: All before MU106
- **Vulnerability Type (CWE)**: Missing Password Field Masking (CVE-549)
- **Report Source**: Report to CERT Polska
## Description
The vulnerability CVE-2025-13175: Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The issue affects Y Soft SafeQ 6 in versions before MU106.
## Credits
Thank you to Hubert Decyusz and Karol Mazurek from AFINETeam for the responsible vulnerability report.
标题: Release Notes Build 106 | YSoft SAFEQ documentation -- 🔗来源链接
标签:release-notes
神龙速读:
### 关键漏洞信息
- **HP Terminal Authentication**
- Added support for card, PIN, and username/password authentication options on Cloud Terminal for HP (SQC-8557)
- **ARM64 Compatibility**
- Improved Client V3 and Flexispooler installers to fully support ARM64 devices, ensuring error-free installation and automatic print queue creation (SQC-8561)
- **Upgraded Tomcat**
- Upgraded Tomcat to version 9.0.102 to address potential vulnerabilities and improve overall security (SBT-5136)
### 其他改进
- **Corrected broken links**
- Corrected broken links in SafeQ 6 documentation caused by references to unpublished internal Confluence pages (SBT-5165)
- **Password fields masking**
- Password fields in Workflow Connectors are now properly masked to prevent exposure in browser inspection tools (SBT-5146)
- **Fixed extra backslashes**
- Corrected an issue where extra backslashes were added to path values in spooler.config during FSP service startup (SBT-5112)
标题: No Print Management with SAFEQ Cloud | YSoft SAFEQ -- 🔗来源链接
标签:product
神龙速读:
- **产品涉及**: 无打印管理,云打印服务
- **漏洞关键信息**: 无直接显示漏洞信息,但需关注YSoft SAFEQ Cloud云服务的管理层面与数据安全规范,例如云环境下的访问控制、数据加密、身份验证等
- **预防措施**: 提供“START DEMO”和“TRY INTEGRATED MFP”按钮,可能需要谨慎对待在线演示服务的使用,以规避潜在的网络钓鱼或恶意软件风险
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.