Missing Authorization Vulnerability in Zara 4 Image Compression by Patchstack
CVE-2025-49969
4.3MEDIUM
What is CVE-2025-49969?
A missing authorization flaw in Zara 4 Image Compression allows unauthorized users to exploit improperly configured access control security levels. This vulnerability affects versions from n/a to 1.2.17.2, potentially exposing sensitive functionality to unauthorized access. Administrators are advised to review their configurations and apply necessary security patches to safeguard against this exploit.
Affected Version(s)
Zara 4 Image Compression <= 1.2.17.2