Unprotected Access Vulnerability in Epsilon RH by Grupo Castilla
CVE-2025-12461
6.9MEDIUM
What is CVE-2025-12461?
This vulnerability enables attackers to gain unauthorized access to sensitive information within the Epsilon RH application. By exploiting the lack of access controls, an attacker can directly access certain components of the application, such as the '/epsilonnet/License/About.aspx' path, revealing confidential license and configuration details. Knowing which modules are installed allows them to glean crucial information, putting both the product and its users at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Epsilon RH 3.03.36.0185
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Oscar Atienza
