PT-2025-18213 · Unknown · Khc-Invitation-Automation
Ekrishnachaitanya2004
·
Published
2025-04-29
·
Updated
2025-04-30
·
CVE-2025-46552
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
KHC-INVITATION-AUTOMATION version 1.2
Description
The issue concerns a GitHub automation script where user data, including email addresses and Discord usernames, were exposed in API responses without proper access controls. This allowed unauthorized users to access sensitive user information by directly calling specific endpoints.
Recommendations
For KHC-INVITATION-AUTOMATION version 1.2, update to a later commit where the issue has been patched to resolve the problem. As a temporary workaround, consider restricting access to the API endpoints that expose user data until the update is applied.
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Khc-Invitation-Automation