PT-2025-7805 · Unknown · Benner Modernanet
Y4G0
+1
·
Published
2025-02-25
·
Updated
2025-02-25
·
CVE-2025-1642
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Benner ModernaNet versions 1.1.0 and earlier
Description
A critical issue has been identified in Benner ModernaNet, affecting unknown code in the file /AGE0000700/GetImageMedico?fooId=1. The manipulation of the
fooId argument leads to improper control of resource identifiers, allowing remote attacks. Upgrading to version 1.1.1 can address this issue.Recommendations
For Benner ModernaNet versions 1.1.0 and earlier, upgrade to version 1.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the /AGE0000700/GetImageMedico API endpoint until the update is applied. Avoid using the
fooId argument in the affected API endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Benner Modernanet