Metrics
Affected Vendors & Products
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orionsec
Orionsec orion-ops |
|
| Vendors & Products |
Orionsec
Orionsec orion-ops |
Mon, 01 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserController.java of the component User Profile Handler. This manipulation of the argument ID causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | orionsec orion-ops User Profile UserController.java update improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-01T05:02:05.640Z
Updated: 2025-12-01T14:46:12.906Z
Reserved: 2025-11-30T14:25:25.295Z
Link: CVE-2025-13808
Updated: 2025-12-01T14:45:57.524Z
Status : Awaiting Analysis
Published: 2025-12-01T05:16:04.070
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-13808
No data.