Beveiligingsadvies

CVE-2025-0740

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-01-30 11:11:24
Laatst bijgewerkt 2025-01-30 14:58:52
Toegewezen door INCIBE
CVSS-score 8.6
Status PUBLISHED

Beschrijving

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing the “CHAT_ID” of the endpoint "/embedai/chats/load_messages?chat_id=<CHAT_ID>".