PT-2025-22350 · Unknown · Konsola Proget

Marcin Węgłowski

·

Published

2025-05-21

·

Updated

2025-05-21

·

CVE-2025-1418

CVSS v4.0

5.1

Medium

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Konsola Proget versions prior to 2.17.5
Description A low-privileged user can access information about profiles created in Proget MDM, which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information, including their usage in connected devices.
Recommendations For versions prior to 2.17.5, update to version 2.17.5 to resolve the issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-1418

Affected Products

Konsola Proget