PT-2025-51251 · Newgen · Newgen Omnidocs
Cbx216
·
Publicado
2025-12-15
·
Atualizado
2025-12-15
·
CVE-2025-65742
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Newgen OmniDocs version 11.0
Description
An unauthenticated Broken Function Level Authorization (BFLA) exists in Newgen OmniDocs v11.0. This allows attackers to obtain sensitive information and execute a full account takeover by sending a specially crafted API request. The vulnerability occurs due to insufficient authorization checks, enabling unauthorized access to functionality.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Newgen Omnidocs