PT-2025-44425 · Senza · Senza

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2025-61117

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Senza versions 2.10.15
Description The Senza: Keto & Fasting Android App has an issue with how it controls access to user data. Insufficient checks in the app’s API endpoints allow attackers to get authentication tokens and take over accounts. This could lead to unauthorized access to accounts, privacy breaches, and misuse of the platform. The vulnerable API endpoints allow attackers to bypass intended access restrictions.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-61117

Affected Products

Senza