CVE-2025-43947

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 284

Summary

CVE-2025-43947 is a vulnerability affecting Codemers KLIMS 1.6.DEV. This issue stems from insufficient access controls, granting regular KLIMS users the ability to execute admin functions. These capabilities encompass modifying configurations, creating user accounts, and uploading files, among various other privileged actions. Consequently, an attacker who manages to compromise a standard user account can effectively gain administrative control over the system. This situation poses a significant security risk, as it can enable unauthorized modifications, data theft, and potential system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share