An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint includes IP address, userAgent and location of the user that visited the web page.
References
Configurations
No configuration.
History
18 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE |
30 Jan 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 |
30 Jan 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-30 12:15
Updated : 2025-02-18 19:15
NVD link : CVE-2025-0743
Mitre link : CVE-2025-0743
CVE.ORG link : CVE-2025-0743
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control