PT-2025-17001 · Unknown · Scott Taylor Avatar

Nguyen Xuan Chien

·

Published

2025-04-17

·

Updated

2025-04-19

·

CVE-2025-39434

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Scott Taylor Avatar versions 0.1.4 and earlier
Description The issue affects the access control security levels in Scott Taylor Avatar, allowing exploitation through incorrectly configured security levels. This is due to an Authorization Bypass Through User-Controlled Key vulnerability.
Recommendations For versions 0.1.4 and earlier, update to a version that fixes the Authorization Bypass Through User-Controlled Key vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-39434

Affected Products

Scott Taylor Avatar