← Back

CVE-2025-65900

nvd nist
Published: Dec 4, 2025Modified: Dec 10, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.

Affected (1)

Products: Difuse: Kalmia
1 product
Kalmia
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.2.0

References (2)

Source: cve@mitre.org
Product
Source: cve@mitre.org
ExploitThird Party Advisory

Timeline

No history available yet.