Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. This includes the actual token, although only the hashed token. This does not include any un-hashed authentication token as viewable. This issue has been patched in version 1.21.0. A workaround for this is not deemed viable as it would involve disabling token authentication. Users are encouraged to remove any authentication token that was created by one of the effected versions of Centurion ERP. Webmasters can ensure this occurs by removing all authentication tokens from the database.
History

Tue, 02 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 31 Aug 2025 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Nofusscomputing
Nofusscomputing centurion Erp
Vendors & Products Nofusscomputing
Nofusscomputing centurion Erp

Fri, 29 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
Description Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. This includes the actual token, although only the hashed token. This does not include any un-hashed authentication token as viewable. This issue has been patched in version 1.21.0. A workaround for this is not deemed viable as it would involve disabling token authentication. Users are encouraged to remove any authentication token that was created by one of the effected versions of Centurion ERP. Webmasters can ensure this occurs by removing all authentication tokens from the database.
Title Centurion ERP users can view hashed authentication tokens that belong to other users
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-02T19:22:22.110Z

Reserved: 2025-08-27T13:34:56.185Z

Link: CVE-2025-58156

cve-icon Vulnrichment

Updated: 2025-09-02T19:22:17.598Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-29T22:15:32.513

Modified: 2025-09-02T15:55:35.520

Link: CVE-2025-58156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-31T08:41:35Z