Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry out administrative functions and manipulate data of other users via unauthorized API calls.
References
| Link | Resource |
|---|---|
| https://no-sec.net/posts/cve-2025-61075/ | Exploit Third Party Advisory |
| https://www.adata.de/mitarbeiter-portal/ | Product |
Configurations
History
No history.
Information
Published : 2025-12-09 16:18
Updated : 2025-12-12 14:43
NVD link : CVE-2025-61075
Mitre link : CVE-2025-61075
CVE.ORG link : CVE-2025-61075
JSON object : View
Products Affected
adata
- mitarbeiter_portal
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
