PT-2025-16145 · Unknown · Oz Forensics

Published

2025-04-11

·

Updated

2025-04-13

·

CVE-2025-32367

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Oz Forensics face recognition application versions prior to 4.0.8
Description: The issue allows PII retrieval via /statistic/list Insecure Direct Object Reference.
Recommendations: For versions prior to 4.0.8, consider disabling access to the /statistic/list endpoint until a patch is available. As a temporary workaround, restrict the use of the Insecure Direct Object Reference functionality to minimize the risk of exploitation. Avoid using the vulnerable endpoint until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-32367

Affected Products

Oz Forensics