CVE-2025-30352
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 200
Summary
CVE-2025-30352 is a vulnerability affecting Directus, a real-time API and App dashboard for managing SQL database content. In versions prior to 11.5.0, including 9.0.0-alpha.4, the search query parameter enables users with collection access to filter items based on unpermitted fields. This issue arises due to a lack of permission checks on searchable columns. As a result, unauthorized users can potentially enumerate content from unpermitted fields, leading to potential data leakage. The vulnerability has been resolved in version 11.5.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.