Medium severity6.5NVD Advisory· Published Jan 4, 2026· Updated Jul 20, 2026
CVE-2025-3660
CVE-2025-3660
Description
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.7.31
- Petlibrio/Smart Pet Feeder Platformv5Range: Unknown
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.