Improper Access Control in EmbedAI by Incibe
CVE-2025-0744
7.5HIGH
What is CVE-2025-0744?
An Improper Access Control vulnerability exists in EmbedAI versions 2.1 and earlier, allowing authenticated users to exploit the system. Through a crafted POST request to the '/demos/embedai/pmt_cash_on_delivery/pay' endpoint, an attacker can alter their subscription plan without the need for payment, leading to potential financial losses for the service provider.
Affected Version(s)
EmbedAI 0 < 2.1