Metrics
Affected Vendors & Products
Thu, 21 Aug 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. | An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable platform accepts a responsibility over protecting the data of their application. |
Wed, 25 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 11 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 30 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-05-30T00:00:00.000Z
Updated: 2025-08-21T02:28:45.607Z
Reserved: 2025-05-25T00:00:00.000Z
Link: CVE-2025-48757
Updated: 2025-05-30T12:48:39.892Z
Status : Undergoing Analysis
Published: 2025-05-30T03:15:20.893
Modified: 2025-08-21T03:15:29.427
Link: CVE-2025-48757
No data.