CVE-2025-23486

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 22, 2025
CWE ID 862

Summary

CVE-2025-23486 is a security vulnerability affecting the NotFound Database Sync application. This issue involves a missing authorization control, allowing unauthorized access to certain functionalities. Specifically, incorrectly configured access control security levels can be exploited, potentially leading to data manipulation or unauthorized data access. The vulnerability affects all versions of Database Sync from n/a through 0.5.1. It is crucial for users to apply the necessary patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share