Authorization Bypass Vulnerability in eyecix JobSearch by eyecix
CVE-2025-49978
4.3MEDIUM
What is CVE-2025-49978?
An authorization bypass vulnerability has been identified in the eyecix JobSearch plugin, enabling attackers to exploit improperly configured access control levels. This vulnerability allows unauthorized users to bypass intended security measures, potentially leading to unauthorized access to sensitive user information. The issue affects JobSearch versions from n/a through 2.9.0, highlighting the need for prompt updates and security assessments in all implementations.
Affected Version(s)
JobSearch <= 2.9.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)