PT-2025-48412 · Orionsec · Orion-Ops

Sh7Err03

·

Published

2025-12-01

·

Updated

2025-12-06

·

CVE-2025-13808

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions orionsec orion-ops versions up to 5925824997a3109651bbde07460958a7be249ed1
Description A flaw exists in orionsec orion-ops. The issue is related to improper authorization caused by manipulation of the ID argument within the update function located in the UserController.java file of the User Profile Handler component. This manipulation can be carried out remotely. An exploit for this issue has been published. The vendor was contacted regarding this disclosure but did not respond.
Recommendations Versions up to 5925824997a3109651bbde07460958a7be249ed1 should be updated. As a temporary workaround, consider restricting access to the update function within the UserController.java file until a patch is available.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-13808

Affected Products

Orion-Ops