PT-2025-32468 · Unknown · Litmuschaos Litmus

Maique

·

Published

2025-08-10

·

Updated

2025-08-13

·

CVE-2025-8794

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LitmusChaos Litmus versions prior to 3.19.1
Description: A problematic issue exists in the LocalStorage Handler component of LitmusChaos Litmus. Manipulation of the projectID argument can lead to authorization bypass. Local access is required for exploitation. The details of this issue have been publicly disclosed, and the vendor did not respond to early disclosure attempts.
Recommendations: Update LitmusChaos Litmus to version 3.19.1 or later.

Exploit

Fix

Improper Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-8794

Affected Products

Litmuschaos Litmus