Improper Access Control in EmbedAI Software by EmbedAI Inc.
CVE-2025-0743

5.3MEDIUM

Key Information:

Vendor
Embedai
Status
Vendor
CVE Published:
30 January 2025

Summary

An Improper Access Control vulnerability exists in EmbedAI versions up to 2.1. This flaw permits an authenticated attacker to exploit the endpoint '/embedai/visits/show/<VISIT_ID>', enabling them to retrieve sensitive information about other users' visits. The exposed data includes critical details such as the user's IP address, user agent, and geographical location, potentially leading to privacy breaches and further malicious activity.

Affected Version(s)

EmbedAI 0 < 2.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David UtĂłn Amaya (m3n0sd0n4ld)
.