CVE-2025-31618
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 862
Summary
CVE-2025-31618 is a Missing Authorization vulnerability affecting the Jaap Jansma Connector to CiviCRM with CiviMcRestFace. This issue arises due to incorrectly configured access control security levels, enabling unauthorized exploitation. The vulnerability afflicts versions of the Connector to CiviCRM with CiviMcRestFace from n/a through 1.0.9. This weakness could potentially be exploited for malicious purposes, underscoring the importance of implementing appropriate access control measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.