PT-2025-17579 · Codemers · Codemers Klims
Published
2025-04-22
·
Updated
2025-04-23
·
CVE-2025-43947
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Codemers KLIMS version 1.6.DEV
Description
The issue is related to a lack of proper access control mechanism, allowing a normal user to perform actions that are typically restricted to administrators. This includes modifying the configuration, creating users, uploading files, and other administrative tasks.
Recommendations
For Codemers KLIMS version 1.6.DEV, consider restricting access to sensitive features and administrative tasks until a proper access control mechanism is implemented. As a temporary workaround, limit the actions that normal users can perform to minimize the risk of unauthorized modifications or data uploads.
Exploit
Fix
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codemers Klims