PT-2025-51251 · Newgen · Newgen Omnidocs

Cbx216

·

Publicado

2025-12-15

·

Atualizado

2025-12-15

·

CVE-2025-65742

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Newgen OmniDocs version 11.0
Description An unauthenticated Broken Function Level Authorization (BFLA) exists in Newgen OmniDocs v11.0. This allows attackers to obtain sensitive information and execute a full account takeover by sending a specially crafted API request. The vulnerability occurs due to insufficient authorization checks, enabling unauthorized access to functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-65742

Produtos afetados

Newgen Omnidocs