CVE-2025-24693
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-24693 is a Missing Authorization vulnerability affecting the Yehi Advanced Notifications system. This issue arises due to incorrectly configured access control security levels, enabling unauthorized users to exploit the system. The vulnerability spans from version 1.2.7 and older, putting a significant number of users at risk. Unauthorized access could lead to potential data breaches, system disruptions, or unintended modifications. Users are strongly urged to update their systems to the latest version and review their access control policies to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.