PT-2025-16941 · Unknown · Continuous Compliance

CVE-2025-3113

·

Published

2025-04-17

·

Updated

2025-12-03

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Continuous Compliance (affected versions not specified)
Description A valid, authenticated user with sufficient privileges can leverage the application's built-in Connector functionality to access Continuous Compliance's internal database, allowing them to explore the internal database schema and export its data, including the properties of Connecters and Rule Sets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3113

Affected Products

Continuous Compliance