7.5

CVE-2025-45237

Exploit
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dbsyncer ProjectDbsyncer Version2.0.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.296
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://github.com/86dbs/dbsyncer
Product
https://gist.github.com/chao112122/11cd0cc46f0c806856f375f9f3f410c6
Third Party Advisory
Exploit