PT-2025-44427 · Karely L.L.C. · Kanova

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2025-61119

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kanova versions 1.0.27
Description The Kanova Android App has issues with how access is controlled. An attacker could manipulate parameters in requests to the application's API and gain unauthorized access to user details and group information, including entry codes. This could lead to privacy breaches and unauthorized access to groups. The affected application package name is com.karelane and it is developed by Karely L.L.C.
Recommendations Update to a newer version of the Kanova Android App that addresses the access control issues.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-61119

Affected Products

Kanova