Access Control Vulnerability in Kiotviet KiotViet Sync Product
CVE-2025-62978
4.3MEDIUM
What is CVE-2025-62978?
The KiotViet Sync product is affected by a missing authorization vulnerability that allows improper access control, enabling attackers to exploit configurations that offer inadequate security measures. This vulnerability is present in versions of KiotViet Sync up to and including 1.8.5, potentially exposing sensitive operations to unauthorized users.
Affected Version(s)
KiotViet Sync <= n/a