PT-2025-52448 · Unknown · Turms Im Server
Xzzz111
·
Published
2025-12-19
·
Updated
2026-01-02
·
CVE-2025-66911
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Turms IM Server versions prior to 0.10.0-SNAPSHOT
Description
The software contains a flaw in access control related to querying user online status. An authenticated user can access online status, device information, and login timestamps of any user without authorization. The
handleQueryUserOnlineStatusesRequest() method within the UserServiceController.java file is affected.Recommendations
Update to a version newer than 0.10.0-SNAPSHOT.
Exploit
Fix
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Turms Im Server