PT-2025-44030 · Unknown · Turbotenant
Published
2025-10-27
·
Updated
2025-10-28
·
CVE-2025-62516
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TurboTenant versions prior to 2.0.0
Description
A security issue exists in the TurboTenant landlord onboarding and rental signup system, specifically within the property listing activation workflow. This issue could allow unauthorized access to Stripe payment session data, potentially exposing sensitive business metadata, including landlord dashboard sync details and tenant information. The affected functionality involves API endpoints responsible for property listing activation, subscription metadata, and payment link generation.
Recommendations
Update to a version newer than 2.0.0.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Turbotenant