Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the parameters of the search function.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the parameters of the search function. | |
| Weaknesses | CWE-472 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-08-20T04:57:37.466Z
Updated: 2025-08-20T17:39:58.306Z
Reserved: 2025-07-24T23:48:13.065Z
Link: CVE-2025-54551
Updated: 2025-08-20T17:37:57.611Z
Status : Awaiting Analysis
Published: 2025-08-20T05:15:28.057
Modified: 2025-08-20T14:39:07.860
Link: CVE-2025-54551
No data.