It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for other roles. The vulnerability has been identified at least in the file or path ‘/app/tools.html’.
History

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for other roles. The vulnerability has been identified at least in the file or path ‘/app/tools.html’.
Title Inadequate access control in Beta10
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-01-23T15:26:16.067Z

Updated: 2025-02-12T20:41:26.532Z

Reserved: 2025-01-22T10:54:44.386Z

Link: CVE-2025-0637

cve-icon Vulnrichment

Updated: 2025-02-12T20:34:43.994Z

cve-icon NVD

Status : Received

Published: 2025-01-23T16:15:36.617

Modified: 2025-01-23T16:15:36.617

Link: CVE-2025-0637

cve-icon Redhat

No data.