PT-2025-20298 · Insa-Auth · Insa-Auth

Mubelotix

·

Published

2025-05-07

·

Updated

2025-05-07

·

CVE-2025-46826

CVSS v4.0

1.3

Low

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:D/RE:L/U:X
Name of the Vulnerable Software and Affected Versions insa-auth (affected versions not specified)
Description The issue concerns an authentication server for INSA Rouen, where a minor problem allowed third-party websites to access the server's secondary authentication bridge. This could potentially reveal basic student information, such as name and number. However, the issue posed minimal risk, was never exploited, and had limited impact.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-46826
GHSA-63XR-GVJV-R6XV

Affected Products

Insa-Auth