CVE-2025-23486
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 22, 2025
CWE ID 862
Summary
CVE-2025-23486 is a security vulnerability affecting the NotFound Database Sync application. This issue involves a missing authorization control, allowing unauthorized access to certain functionalities. Specifically, incorrectly configured access control security levels can be exploited, potentially leading to data manipulation or unauthorized data access. The vulnerability affects all versions of Database Sync from n/a through 0.5.1. It is crucial for users to apply the necessary patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.