This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API request URL to gain unauthorized access to other user accounts.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Mar 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API request URL to gain unauthorized access to other user accounts. | |
| Title | Improper Access Control Vulnerability in CAP back office application | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published: 2025-03-13T11:21:17.016Z
Updated: 2025-03-13T19:34:11.857Z
Reserved: 2025-03-13T06:38:16.283Z
Link: CVE-2025-29997
Updated: 2025-03-13T19:34:07.573Z
Status : Received
Published: 2025-03-13T12:15:14.127
Modified: 2025-03-13T12:15:14.127
Link: CVE-2025-29997
No data.