Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email.
History

Mon, 17 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 10:30:00 +0000

Type Values Removed Values Added
Description Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email.
Title Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-03-17T10:14:37.246Z

Updated: 2025-03-17T12:15:05.683Z

Reserved: 2025-03-11T09:52:10.472Z

Link: CVE-2025-2202

cve-icon Vulnrichment

Updated: 2025-03-17T12:14:44.223Z

cve-icon NVD

Status : Received

Published: 2025-03-17T11:15:37.970

Modified: 2025-03-17T11:15:37.970

Link: CVE-2025-2202

cve-icon Redhat

No data.