Authorization Flaw in Vitepos by Appsbd
CVE-2025-26750
6.5MEDIUM
Key Information:
- Vendor
- Appsbd
- Status
- Vitepos
- Vendor
- CVE Published:
- 22 February 2025
Summary
A critical missing authorization vulnerability in Appsbd's Vitepos application lets unauthorized users exploit incorrectly set access control security levels. This flaw can potentially allow attackers to gain access to restricted features, compromising the integrity and confidentiality of the system. Affected versions include Vitepos 3.1.3 and earlier. It is essential for organizations using this product to apply necessary patches and mitigate risks associated with this vulnerability.
Affected Version(s)
Vitepos <= 3.1.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Phat RiO - BlueRock (Patchstack Alliance)