PT-2025-38716 · Unknown · Profession Fit+1

Published

2025-09-22

·

Updated

2025-09-23

·

CVE-2025-59797

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Profession Fit version 5.0.99 Build 44910
Description The software allows bypassing authorization controls through direct requests to specific API endpoints and URLs. Specifically, a direct request to the /api/challenges/{id} endpoint allows unauthorized access. Access is also possible via direct URL access to the eversports page, the user-management page, and the plane page. The vulnerable parameter is id.
Recommendations Restrict access to the /api/challenges/{id} endpoint. Restrict direct access to the eversports page. Restrict direct access to the user-management page. Restrict direct access to the plane page.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-59797

Affected Products

Profession Fit
Eversports