CVE-2025-0861

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jan 30, 2025
Updated: Jan 31, 2025
CWE ID 89

Summary

CVE-2025-0743 is an Improper Access Control vulnerability affecting EmbedAI versions 2.1 and below. This issue enables authenticated attackers to gain unauthorized access to visit information of other users. The endpoint "/embedai/visits/show/<VISIT_ID>" is exploited to retrieve sensitive data such as IP addresses, userAgents, and locations of users who have visited a particular webpage. This vulnerability poses a significant risk to user privacy and security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share