PT-2025-18213 · Unknown · Khc-Invitation-Automation

Ekrishnachaitanya2004

·

Published

2025-04-29

·

Updated

2025-04-30

·

CVE-2025-46552

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions KHC-INVITATION-AUTOMATION version 1.2
Description The issue concerns a GitHub automation script where user data, including email addresses and Discord usernames, were exposed in API responses without proper access controls. This allowed unauthorized users to access sensitive user information by directly calling specific endpoints.
Recommendations For KHC-INVITATION-AUTOMATION version 1.2, update to a later commit where the issue has been patched to resolve the problem. As a temporary workaround, consider restricting access to the API endpoints that expose user data until the update is applied.

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-46552
GHSA-7MPF-6GG2-2FJP

Affected Products

Khc-Invitation-Automation