CVE-2024-12125

A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.
Configurations

No configuration.

History

14 Nov 2025, 13:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.5

13 Nov 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 6.5
Summary (en) A flaw was found in the 3scale developer portal. This issue can allow account creation or updates passed through hidden or read-only fields, the contents of which may be altered. This flaw allows an attacker to access or modify restricted information. (en) A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.

06 Nov 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-06 22:15

Updated : 2025-11-14 13:15


NVD link : CVE-2024-12125

Mitre link : CVE-2024-12125

CVE.ORG link : CVE-2024-12125


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions