Description
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6768 | Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords. |
References
| Link | Providers |
|---|---|
| https://gitee.com/r1bbit/yimioa/issues/IBI7PG |
|
History
Thu, 19 Jun 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
R1bbit
R1bbit yimioa |
|
| CPEs | cpe:2.3:a:r1bbit:yimioa:*:*:*:*:*:*:*:* | |
| Vendors & Products |
R1bbit
R1bbit yimioa |
Wed, 19 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 18 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-19T18:24:48.078Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25585
Updated: 2025-03-19T14:39:21.002Z
Status : Analyzed
Published: 2025-03-18T15:16:00.253
Modified: 2025-06-19T00:16:52.923
Link: CVE-2025-25585
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD