PT-2025-24132 · Unknown · Email Subscribe Form

Hiro

·

Published

2025-06-06

·

Updated

2025-06-06

·

CVE-2025-28985

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Elastic Email Subscribe Form versions 1.2.2 and earlier
Description The issue is related to a Missing Authorization vulnerability in the Elastic Email Subscribe Form, which allows exploitation due to incorrectly configured access control security levels.
Recommendations For Elastic Email Subscribe Form versions 1.2.2 and earlier, update to a version that includes the necessary security patches to fix the Missing Authorization vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-28985

Affected Products

Email Subscribe Form