PT-2025-13649 · Unknown · Customer Portal

Published

2025-03-31

·

Updated

2025-04-01

·

CVE-2025-3013

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Customer Portal versions prior to 2.1.4
Description The issue is related to Insecure Direct Object References (IDOR) in access control, allowing an attacker to access sensitive information by manipulating request parameters or object references. This can be exploited by attackers to gain unauthorized access.
Recommendations For versions prior to 2.1.4, update to version 2.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive objects and parameters to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-3013

Affected Products

Customer Portal