CVE-2025-22592

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 862

Summary

CVE-2025-22592 is a security vulnerability affecting the Lenderd 1003 Mortgage Application. This issue involves missing authorization controls, which enable unauthorized access to functionality that is not properly constrained by Access Control Lists (ACLs). Consequently, malicious actors can bypass intended access restrictions, potentially leading to data breaches or system manipulation. This vulnerability affects versions of the 1003 Mortgage Application from n/a through 1.87.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share