PT-2025-47564 · Romm · Romm
Published
2025-11-20
·
Updated
2025-12-03
·
CVE-2025-65096
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RomM versions prior to 4.4.1
RomM version 4.4.1-beta.2
Description
RomM (ROM Manager) enables users to manage their game collections through a user interface. A flaw exists where users can access private or smart collections belonging to other users by directly using their IDs through an API. The system does not verify ownership or check if a collection is public before returning collection data. The API endpoint allowing this access is not specified. The vulnerable parameter is the collection ID.
Recommendations
Update RomM to version 4.4.1 or 4.4.1-beta.2.
Exploit
Fix
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Romm