Security Advisory

CVE-2025-65900

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-04 00:00:00
Last updated 2025-12-05 20:30:46
Assigner mitre
State PUBLISHED

Description

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.