PT-2025-49250 · Unknown · Himool Erp

Alunxzhou

·

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2025-14089

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Himool ERP versions up to 2.2
Description A security issue exists in Himool ERP. This issue involves improper authorization due to manipulation of the update account function within the AdminActionViewSet component. The vulnerable file is located at the API endpoint '/api/admin/update account/'. The issue is remotely exploitable and the exploit is publicly available.
Recommendations Versions prior to 2.3 should be updated. As a temporary workaround, consider restricting access to the '/api/admin/update account/' API endpoint until a patch is available.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-14089

Affected Products

Himool Erp