CVE-2025-27422
CVE-2025-27422
Título es
CVE-2025-27422
Lun, 03/03/2025 – 17:15
Tipo
CWE-287
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-27422
Descripción en
FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information, secure password, etc) but there are no other controls stopping them. This vulnerability is fixed in 1.4.3.
03/03/2025
03/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
7.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
https://github.com/factionsecurity/faction/commit/0a6848d388d6dba1c81918cce2772b1e805cd3d6
https://github.com/factionsecurity/faction/security/advisories/GHSA-97cv-f342-v2jc
Enviar en el boletín
Off