Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.
References
| Link | Resource |
|---|---|
| https://de.linkedin.com/company/codemers | Product |
| https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43947 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-04-22 18:16
Updated : 2025-06-23 17:59
NVD link : CVE-2025-43947
Mitre link : CVE-2025-43947
CVE.ORG link : CVE-2025-43947
JSON object : View
Products Affected
codemers
- klims
CWE
CWE-284
Improper Access Control
