Sensitive API Exposure in Web Application Affects User Privileges
CVE-2025-54766

5.3MEDIUM

Key Information:

Vendor

Xorux

Status
Vendor
CVE Published:
29 July 2025

What is CVE-2025-54766?

A vulnerability exists in the API endpoint of the web application, granting unintended access to lower-level read-only users. Despite being designed for use by administrators, these users can exploit this endpoint to export critical appliance configurations, potentially leading to the exposure of sensitive information. This risk underscores the importance of robust access control measures to safeguard sensitive data from unauthorized access.

Affected Version(s)

XorMon-NG Linux 1.8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.