Sensitive API Exposure in Web Application Affects User Privileges
CVE-2025-54766
5.3MEDIUM
What is CVE-2025-54766?
A vulnerability exists in the API endpoint of the web application, granting unintended access to lower-level read-only users. Despite being designed for use by administrators, these users can exploit this endpoint to export critical appliance configurations, potentially leading to the exposure of sensitive information. This risk underscores the importance of robust access control measures to safeguard sensitive data from unauthorized access.
Affected Version(s)
XorMon-NG Linux 1.8