PT-2025-9523 · Faction · Faction

Sa7Mon

·

Published

2025-03-03

·

Updated

2025-03-05

·

CVE-2025-27422

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FACTION versions prior to 1.4.3
Description The issue allows an attacker to bypass authentication by registering a new user with admin privileges at any time without authorization. The registration request must follow validation rules, such as providing all required information and using a secure password, but there are no additional controls to prevent this action.
Recommendations For versions prior to 1.4.3, update to version 1.4.3 to resolve the issue.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27422
GHSA-97CV-F342-V2JC

Affected Products

Faction