Improper Access Control in EmbedAI Affects User Chat Functionality
CVE-2025-0741
5.8MEDIUM
Key Information:
- Vendor
- Embedai
- Status
- Embedai
- Vendor
- CVE Published:
- 30 January 2025
Summary
An Improper Access Control vulnerability has been identified in EmbedAI versions 2.1 and below. This security flaw allows an authenticated attacker to manipulate the 'chat_id' parameter in a POST request to the '/embedai/chats/send_message' endpoint. As a result, attackers can send messages within other users' chat sessions, potentially leading to unauthorized access to sensitive communications and disrupting user experiences. Addressing this vulnerability is crucial for ensuring the integrity and security of user interactions in the platform.
Affected Version(s)
EmbedAI 0 < 2.1
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
David Utón Amaya (m3n0sd0n4ld)