PT-2025-43457 · Unknown · Notificationstation

Published

2025-08-12

·

Updated

2025-12-08

·

CVE-2025-48555

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NotificationStation (affected versions not specified)
Description The software contains a possible cross-profile information disclosure due to a confused deputy condition in multiple functions of NotificationStation.java. This issue could lead to local escalation of privilege without requiring additional execution privileges or user interaction. The vulnerable functions are located at https://t.co/jFLr70O7HO. A confused deputy occurs when a program unintentionally performs an action on behalf of another program, potentially leading to unauthorized access or modification of data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ASB-A-396666065
BDU:2026-00772
CVE-2025-48555

Affected Products

Notificationstation