PT-2025-43974 · Hubspot · Hubspot
CVE-2023-37749
·
Publicado
2025-10-27
·
Atualizado
2025-10-27
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HubSpot version 1.29441
Description
An issue exists in the REST API endpoint of HubSpot that allows unauthenticated attackers to view users' data without proper authorization due to incorrect access control. The API endpoint ''/api/v1/users'' is vulnerable. The vulnerable parameter is
user id.Recommendations
Apply updated access controls to the REST API endpoint to ensure proper authentication and authorization mechanisms are in place. Restrict access to the API endpoint ''/api/v1/users'' to authenticated users only.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hubspot