VYPR

cm3

by Ddsn

CVEs (1)

  • CVE-2025-25968MedFeb 20, 2025
    risk 0.39cvss 6.0epss 0.01

    DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By…