PT-2025-40858 · Sick Ag+1 · Enterprise Analytics+1
Published
2025-10-06
·
Updated
2025-10-06
·
CVE-2025-58578
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Versions prior to 2025-58578
Description
A user possessing the necessary permissions can create an unlimited number of user accounts through an API endpoint using a POST request. The system lacks quotas, validation, or restrictions to limit account creation. The API endpoint is susceptible to abuse, potentially leading to resource exhaustion or other malicious activities.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enterprise Analytics
Sick