FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information, secure password, etc) but there are no other controls stopping them. This vulnerability is fixed in 1.4.3.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 03 Mar 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information, secure password, etc) but there are no other controls stopping them. This vulnerability is fixed in 1.4.3. | |
Title | FACTION Allows Authentication Bypass via User Creation | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-03T16:25:48.918Z
Updated: 2025-03-03T18:53:10.870Z
Reserved: 2025-02-24T15:51:17.269Z
Link: CVE-2025-27422

Updated: 2025-03-03T18:52:59.136Z

Status : Received
Published: 2025-03-03T17:15:15.787
Modified: 2025-03-03T17:15:15.787
Link: CVE-2025-27422

No data.