CVE-2025-15581
4.7
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a (Secondary)
Description
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation.
Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
References (4)
Source: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
Source: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
Source: ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.