PT-2026-6794 · Deepaudit · Deepaudit
Ez-Lbz
·
Publicado
2026-02-06
·
Atualizado
2026-02-28
·
CVE-2026-25729
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DeepAudit versions prior to 3.0.5
Description
An improper access control issue exists in DeepAudit versions 3.0.4 and earlier. The
/api/v1/users/ API endpoint allows any authenticated user to enumerate all users within the system. This allows retrieval of sensitive information such as email addresses, phone numbers, full names, and role information. The vulnerable parameter is not specified.Recommendations
Update DeepAudit to version 3.0.5 or later.
Exploit
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Deepaudit