PT-2025-7805 · Unknown · Benner Modernanet

Y4G0

+1

·

Published

2025-02-25

·

Updated

2025-02-25

·

CVE-2025-1642

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Benner ModernaNet versions 1.1.0 and earlier
Description A critical issue has been identified in Benner ModernaNet, affecting unknown code in the file /AGE0000700/GetImageMedico?fooId=1. The manipulation of the fooId argument leads to improper control of resource identifiers, allowing remote attacks. Upgrading to version 1.1.1 can address this issue.
Recommendations For Benner ModernaNet versions 1.1.0 and earlier, upgrade to version 1.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the /AGE0000700/GetImageMedico API endpoint until the update is applied. Avoid using the fooId argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1642

Affected Products

Benner Modernanet