PT-2025-16941 · Unknown · Continuous Compliance

Published

2025-04-17

·

Updated

2025-12-03

·

CVE-2025-3113

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Continuous Compliance (affected versions not specified)
Description A valid, authenticated user with sufficient privileges can leverage the application's built-in Connector functionality to access Continuous Compliance's internal database, allowing them to explore the internal database schema and export its data, including the properties of Connecters and Rule Sets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-3113

Affected Products

Continuous Compliance