CVE-2025-43947
CVSS 3.1 Score 7.3 of 10 (high)
Details
Summary
CVE-2025-43947 is a vulnerability affecting Codemers KLIMS 1.6.DEV. This issue stems from insufficient access controls, granting regular KLIMS users the ability to execute admin functions. These capabilities encompass modifying configurations, creating user accounts, and uploading files, among various other privileged actions. Consequently, an attacker who manages to compromise a standard user account can effectively gain administrative control over the system. This situation poses a significant security risk, as it can enable unauthorized modifications, data theft, and potential system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.