A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices).
This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).
This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16002 | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices). This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 21 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices). This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite). | |
| Title | Information disclosure in Proget MDM | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-05-21T13:26:07.661Z
Reserved: 2025-02-18T13:43:47.696Z
Link: CVE-2025-1418
Updated: 2025-05-21T13:26:03.429Z
Status : Awaiting Analysis
Published: 2025-05-21T13:16:01.927
Modified: 2025-05-21T20:24:58.133
Link: CVE-2025-1418
No data.
OpenCVE Enrichment
No data.
EUVD