Beveiligingsadvies

CVE-2025-0744

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-01-30 11:17:25
Laatst bijgewerkt 2025-02-18 19:03:02
Toegewezen door INCIBE
CVSS-score 7.5
Status PUBLISHED

Beschrijving

an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/demos/embedai/pmt_cash_on_delivery/pay" endpoint.