CVE-2025-0743
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 30, 2025
CWE ID 863
CWE ID 284
Summary
CVE-2025-0743 is an Improper Access Control vulnerability affecting EmbedAI versions 2.1 and below. This issue enables authenticated attackers to access information about other users' visits through the endpoint "/embedai/visits/show/<VISIT_ID>". The divulged data includes IP addresses, userAgents, and locations, posing a privacy risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share