Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-6994 | In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 15 Oct 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-287 |
Wed, 15 Oct 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-306 |
Tue, 01 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Infiniflow
Infiniflow ragflow |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:infiniflow:ragflow:0.12.0:*:*:*:*:*:*:* | |
Vendors & Products |
Infiniflow
Infiniflow ragflow |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues. | |
Title | Improper Authentication in infiniflow/ragflow | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-10-15T12:49:32.208Z
Reserved: 2024-12-20T20:12:36.931Z
Link: CVE-2024-12869

Updated: 2025-03-20T14:14:00.557Z

Status : Modified
Published: 2025-03-20T10:15:31.087
Modified: 2025-10-15T13:15:40.930
Link: CVE-2024-12869

No data.

No data.