Vulnerability Details CVE-2025-55194
Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.4%
CVSS Severity
CVSS v3 Score 5.7
Products affected by CVE-2025-55194
-
cpe:2.3:a:part-db_project:part-db:0.3.0
-
cpe:2.3:a:part-db_project:part-db:0.3.1
-
cpe:2.3:a:part-db_project:part-db:0.4.0
-
cpe:2.3:a:part-db_project:part-db:0.4.1
-
cpe:2.3:a:part-db_project:part-db:0.4.2
-
cpe:2.3:a:part-db_project:part-db:0.4.3
-
cpe:2.3:a:part-db_project:part-db:0.4.4
-
cpe:2.3:a:part-db_project:part-db:0.4.5
-
cpe:2.3:a:part-db_project:part-db:0.4.6
-
cpe:2.3:a:part-db_project:part-db:0.5.0
-
cpe:2.3:a:part-db_project:part-db:0.5.1
-
cpe:2.3:a:part-db_project:part-db:0.5.10
-
cpe:2.3:a:part-db_project:part-db:0.5.11
-
cpe:2.3:a:part-db_project:part-db:0.5.2
-
cpe:2.3:a:part-db_project:part-db:0.5.3
-
cpe:2.3:a:part-db_project:part-db:0.5.4
-
cpe:2.3:a:part-db_project:part-db:0.5.5
-
cpe:2.3:a:part-db_project:part-db:0.5.6
-
cpe:2.3:a:part-db_project:part-db:0.5.7
-
cpe:2.3:a:part-db_project:part-db:0.5.8
-
cpe:2.3:a:part-db_project:part-db:0.5.9
-
cpe:2.3:a:part-db_project:part-db:1.0.0
-
cpe:2.3:a:part-db_project:part-db:1.0.1
-
cpe:2.3:a:part-db_project:part-db:1.0.2