In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://archerirm.com |
![]() ![]() |
https://github.com/NastyCrow/CVE-2025-27893 |
![]() ![]() ![]() |
History
Tue, 11 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls. | |
Weaknesses | CWE-472 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-11T00:00:00.000Z
Updated: 2025-03-11T13:37:25.862Z
Reserved: 2025-03-10T00:00:00.000Z
Link: CVE-2025-27893

Updated: 2025-03-11T13:37:18.545Z

Status : Received
Published: 2025-03-11T09:15:25.457
Modified: 2025-03-11T14:15:26.033
Link: CVE-2025-27893

No data.