Improper Access Control in EmbedAI Software by EmbedAI Inc.
CVE-2025-0743
5.3MEDIUM
Summary
An Improper Access Control vulnerability exists in EmbedAI versions up to 2.1. This flaw permits an authenticated attacker to exploit the endpoint '/embedai/visits/show/<VISIT_ID>', enabling them to retrieve sensitive information about other users' visits. The exposed data includes critical details such as the user's IP address, user agent, and geographical location, potentially leading to privacy breaches and further malicious activity.
Affected Version(s)
EmbedAI 0 < 2.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
David UtĂłn Amaya (m3n0sd0n4ld)