9.9

CVE-2025-70982

Exploit
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BladexSpringblade Version4.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.21
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://github.com/chillzhuang/SpringBlade
Product
https://github.com/chillzhuang/SpringBlade/issues/34
Exploit
Issue Tracking
https://gist.github.com/old6ma/ea60151aa40ddc1cfb51fbaa0c173117
Third Party Advisory