CVE-2025-31618

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 862

Summary

CVE-2025-31618 is a Missing Authorization vulnerability affecting the Jaap Jansma Connector to CiviCRM with CiviMcRestFace. This issue arises due to incorrectly configured access control security levels, enabling unauthorized exploitation. The vulnerability afflicts versions of the Connector to CiviCRM with CiviMcRestFace from n/a through 1.0.9. This weakness could potentially be exploited for malicious purposes, underscoring the importance of implementing appropriate access control measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share