VYPR

zeroheight-account-verification-bypass-CVE-2025-65925

by Sneden

CVEs (1)

  • CVE-2025-65925MedDec 30, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to be created without completing the intended email verification step. While unverified accounts could not access product functionality, the behavior bypassed…