Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3660

Опубликовано: 04 янв. 2026
Источник: nvd
CVSS3: 6.5
CVSS3: 8.2
EPSS Низкий

Описание

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:petlibro:petlibro:*:*:*:*:-:*:*:*
Версия до 1.7.31 (включая)

EPSS

Процентиль: 12%
0.00041
Низкий

6.5 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-612

Связанные уязвимости

CVSS3: 6.5
github
около 1 месяца назад

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.

EPSS

Процентиль: 12%
0.00041
Низкий

6.5 Medium

CVSS3

8.2 High

CVSS3

Дефекты

CWE-612