CVE-2025-26201

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Feb 24, 2025
CWE ID 294

Summary

CVE-2025-26201 is a credential disclosure vulnerability affecting GreaterWMS versions 2.1.49 and below. An attacker can exploit this issue by targeting the /staff route, which bypasses authentication, allowing unauthenticated remote users to gain access to sensitive information and potentially escalate privileges. This vulnerability poses a significant risk to system security and should be addressed promptly by updating to the latest version of GreaterWMS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share