YSoft SafeQ 6 password exposure via UI inspection
CVE-2025-13175 allows administrators to extract Workflow Connector passwords through browser developer tools in YSoft SafeQ 6 versions before MU106.
CERT Polska coordinated disclosure of CVE-2025-13175, a vulnerability in YSoft SafeQ 6 print management software that exposes Workflow Connector passwords to administrators with UI access. The flaw stems from improper rendering of the password field, allowing credential extraction through standard browser developer or inspection tools.
The vulnerability affects only YSoft SafeQ 6 deployments using password-protected Workflow Connectors in versions prior to MU106. The issue represents an elevation of privilege scenario where administrators with legitimate UI access can bypass password masking controls. Organizations using affected versions should upgrade to MU106 or later to remediate the exposure.
The vulnerability was responsibly disclosed by researchers Hubert Decyusz and Karol Mazurek from AFINE Team through CERT Polska's coordinated vulnerability disclosure process. While this is a low-severity issue requiring pre-existing administrator access, it could facilitate lateral movement or privilege escalation in environments where Workflow Connector credentials provide access to sensitive systems.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/01/CVE-2025-13175
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free