PT-2025-32468 · Unknown · Litmuschaos Litmus

Maique

·

Publicado

2025-08-10

·

Atualizado

2025-08-13

·

CVE-2025-8794

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LitmusChaos Litmus versions prior to 3.19.1
Description: A problematic issue exists in the LocalStorage Handler component of LitmusChaos Litmus. Manipulation of the projectID argument can lead to authorization bypass. Local access is required for exploitation. The details of this issue have been publicly disclosed, and the vendor did not respond to early disclosure attempts.
Recommendations: Update LitmusChaos Litmus to version 3.19.1 or later.

Exploit

Correção

Improper Authorization

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-8794

Produtos afetados

Litmuschaos Litmus