PT-2025-3992 · Beta10 · Beta10

David Utón Amaya

·

Published

2025-01-23

·

Updated

2025-01-23

·

CVE-2025-0637

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Beta10 software (affected versions not specified)
Description The Beta10 software does not provide proper authorization control in multiple areas of the application, allowing a malicious actor to access private areas and/or areas intended for other roles without authentication. The issue has been identified at least in the file or path /app/tools.html.
Recommendations As a temporary workaround, consider restricting access to the /app/tools.html endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-0637

Affected Products

Beta10