Authorization Flaw in Vitepos by Appsbd
CVE-2025-26750

6.5MEDIUM

Key Information:

Vendor
Appsbd
Status
Vitepos
Vendor
CVE Published:
22 February 2025

Summary

A critical missing authorization vulnerability in Appsbd's Vitepos application lets unauthorized users exploit incorrectly set access control security levels. This flaw can potentially allow attackers to gain access to restricted features, compromising the integrity and confidentiality of the system. Affected versions include Vitepos 3.1.3 and earlier. It is essential for organizations using this product to apply necessary patches and mitigate risks associated with this vulnerability.

Affected Version(s)

Vitepos <= 3.1.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock (Patchstack Alliance)
.