CVE-2025-23955

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 862

Summary

CVE-2025-23955 is a Missing Authorization vulnerability affecting the Xola platform, specifically versions 1.0 through 1.6 of the software. This issue arises due to incorrectly configured access control security levels in xola.com, enabling unauthorized access and potential exploitation by attackers. The vulnerability can result in significant security risks, as it allows attackers to bypass intended access restrictions and gain unauthorized access to sensitive data or functionality. This issue underscores the importance of proper access control configuration in securing web applications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share