It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for other roles. The vulnerability has been identified at least in the file or path ‘/app/tools.html’.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-1801 It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for other roles. The vulnerability has been identified at least in the file or path ‘/app/tools.html’.
Fixes

Solution

The vulnerability has been fixed by the Beta10 team in the latest version of the application.


Workaround

No workaround given by the vendor.

History

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for other roles. The vulnerability has been identified at least in the file or path ‘/app/tools.html’.
Title Inadequate access control in Beta10
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-02-12T20:41:26.532Z

Reserved: 2025-01-22T10:54:44.386Z

Link: CVE-2025-0637

cve-icon Vulnrichment

Updated: 2025-02-12T20:34:43.994Z

cve-icon NVD

Status : Received

Published: 2025-01-23T16:15:36.617

Modified: 2025-01-23T16:15:36.617

Link: CVE-2025-0637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses