6.5
CVE-2025-26138
- EPSS 0.09%
- Veröffentlicht 18.03.2025 00:00:00
- Zuletzt bearbeitet 01.04.2025 20:37:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Systemic-rm ≫ Risk Value Version <= 2.8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.265 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.