Improper Access Control in EmbedAI Software by EmbedAI Inc.
CVE-2025-0743
5.3MEDIUM
What is CVE-2025-0743?
An Improper Access Control vulnerability exists in EmbedAI versions up to 2.1. This flaw permits an authenticated attacker to exploit the endpoint '/embedai/visits/show/<VISIT_ID>', enabling them to retrieve sensitive information about other users' visits. The exposed data includes critical details such as the user's IP address, user agent, and geographical location, potentially leading to privacy breaches and further malicious activity.
Affected Version(s)
EmbedAI 0 < 2.1