CVE-2025-24989
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 19, 2025
Updated: Feb 24, 2025
CWE ID 284
Summary
CVE-2025-24989 is an access control vulnerability affecting Power Pages. It allows unauthorized attackers to bypass user registration controls, potentially elevating privileges over a network. This issue has been addressed in the service, and all affected customers have been notified. Instructions have been provided for these customers to review their sites for potential exploitation and implement cleanup methods. If you have not received a notification, this vulnerability does not affect you.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share