An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.
References
Configurations
No configuration.
History
18 Feb 2026, 15:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/brtsec/public-advisories/tree/main/advisories/CVE-2025-69752 - | |
| CWE | CWE-639 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
12 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-12 16:16
Updated : 2026-02-18 15:18
NVD link : CVE-2025-69752
Mitre link : CVE-2025-69752
CVE.ORG link : CVE-2025-69752
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
