PT-2025-30450 · Unknown · Onyx Enterprise Edition

Geckosecurity

·

Published

2025-07-22

·

Updated

2025-07-22

·

CVE-2025-51479

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Onyx Enterprise Edition version 0.27.0
Description An authorization bypass exists in the update user group function within onyx-dot-app Onyx Enterprise Edition. This allows remote authenticated attackers to modify arbitrary user groups by sending crafted PATCH requests to the /api/manage/admin/user-group/id endpoint. The issue bypasses intended curator-group assignment checks.
Recommendations As a temporary workaround, consider restricting access to the /api/manage/admin/user-group/id endpoint until a patch is available.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-51479

Affected Products

Onyx Enterprise Edition