A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices).
This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).
Metrics
Affected Vendors & Products
References
History
Wed, 21 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices). This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite). | |
| Title | Information disclosure in Proget MDM | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-05-21T13:03:44.656Z
Updated: 2025-05-21T13:26:07.661Z
Reserved: 2025-02-18T13:43:47.696Z
Link: CVE-2025-1418
Updated: 2025-05-21T13:26:03.429Z
Status : Awaiting Analysis
Published: 2025-05-21T13:16:01.927
Modified: 2025-05-21T20:24:58.133
Link: CVE-2025-1418
No data.