PT-2025-7637 · Unknown · Application

Published

2025-02-21

·

Updated

2025-02-21

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Application (affected versions not specified)
Description The issue concerns the lack of authorization checks for the Host parameter, allowing unauthorized access to view profile information of other users. An attacker can exploit this by replacing the Host parameter. The impact is limited to viewing profile information, without the ability to modify or access other data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

GHSA-3HFJ-QCVJ-4HX8

Affected Products

Application