CVE-2025-29557

ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) ExaGrid EX10 6.3 - 7.0.1.P08 es vulnerable a un control de acceso incorrecto en el endpoint de la API MailConfiguration, donde los usuarios con privilegios de nivel de operador pueden emitir una solicitud HTTP para recuperar credenciales SMTP, incluidas contraseñas de texto sin formato.

31 Jul 2025, 20:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

31 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-31 15:15

Updated : 2026-06-17 09:05


NVD link : CVE-2025-29557

Mitre link : CVE-2025-29557

CVE.ORG link : CVE-2025-29557


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control