PT-2025-44426 · Unknown · Mcarfix Motorists App

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2025-61118

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mCarFix Motorists App version 2.3
Description The mCarFix Motorists App has improper access control issues. An attacker can bypass verification to create accounts and, by manipulating sequential numeric IDs, gain unauthorized access to user data and groups. This could lead to the creation of fake accounts, privacy breaches, and misuse of the platform.
Recommendations Apply updates to address the access control vulnerabilities in version 2.3.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-61118

Affected Products

Mcarfix Motorists App