PT-2025-53618 · Getmaxun · Getmaxun

28Hus

·

Published

2025-12-27

·

Updated

2025-12-27

·

CVE-2025-15106

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions getmaxun versions prior to 0.0.28
Description A weakness exists in the Authentication Endpoint component of getmaxun. Specifically, the router.get function within the server/src/routes/auth.ts file is susceptible to improper authorization due to manipulation. This issue can be exploited remotely. The exploit is publicly available. The vendor was notified of this issue but did not respond.
Recommendations Versions prior to 0.0.28 should be updated. As a temporary workaround, consider disabling the router.get function until a patch is available.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-15106

Affected Products

Getmaxun