An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint includes IP address, userAgent and location of the user that visited the web page.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Feb 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |
Thu, 30 Jan 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
Metrics |
ssvc
|
Thu, 30 Jan 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint includes IP address, userAgent and location of the user that visited the web page. | |
Title | Improper Access Control vulnerability in EmbedAI | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-01-30T11:16:46.978Z
Updated: 2025-02-18T19:03:35.811Z
Reserved: 2025-01-27T12:21:49.705Z
Link: CVE-2025-0743

Updated: 2025-01-30T13:48:02.231Z

Status : Awaiting Analysis
Published: 2025-01-30T12:15:27.707
Modified: 2025-02-18T19:15:23.660
Link: CVE-2025-0743

No data.