PT-2025-11108 · Unknown · Aleksis-Core

Martin Cuddy

·

Published

2025-03-12

·

Updated

2025-03-12

·

CVE-2025-25683

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: AlekSIS-Core versions 3.0 through 3.2.1
Description: The issue is related to Incorrect Access Control, allowing unauthenticated users to access all PDF files.
Recommendations: For AlekSIS-Core versions 3.0 through 3.2.1, consider restricting access to PDF files until a patch is available. As a temporary workaround, limit access to sensitive PDF files to minimize the risk of unauthorized access.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-25683

Affected Products

Aleksis-Core