An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.
History

Fri, 07 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-602
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Mar 2025 19:30:00 +0000

Type Values Removed Values Added
Description An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-03-06T00:00:00.000Z

Updated: 2025-03-07T19:45:40.092Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-25497

cve-icon Vulnrichment

Updated: 2025-03-07T19:45:32.441Z

cve-icon NVD

Status : Received

Published: 2025-03-06T20:15:38.290

Modified: 2025-03-07T20:15:38.013

Link: CVE-2025-25497

cve-icon Redhat

No data.