CVE-2025-25968

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Feb 20, 2025
CWE ID 284

Summary

CVE-2025-25968 is a vulnerability affecting DDSN Interactive's cm3 Acora CMS version 10.1.1. This issue involves improper access control, allowing editor-privileged users to access sensitive information such as system administrator credentials. Attackers can exploit this vulnerability by force browsing the endpoint and manipulating the 'file' parameter, potentially leading to account takeover and privilege escalation. By referencing specific files, they can bypass access controls and gain unauthorized access to restricted information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share