Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55462

Опубликовано: 13 янв. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in the Access-Control-Allow-Origin response along with Access-Control-Allow-Credentials: true. This permits malicious third-party websites to perform authenticated cross-origin requests against the Eramba API, including endpoints like /system-api/login and /system-api/user/me. The response includes sensitive user session data (ID, name, email, access groups), which is accessible to the attacker's JavaScript. This flaw enables full session hijack and data exfiltration without user interaction. Eramba versions 3.23.3 and earlier were tested and appear unaffected. The vulnerability is present in default installations, requiring no custom configuration.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:eramba:eramba:3.26.0:*:*:*:community:*:*:*
cpe:2.3:a:eramba:eramba:3.26.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 10%
0.00034
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-942

Связанные уязвимости

CVSS3: 6.5
github
25 дней назад

A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in the Access-Control-Allow-Origin response along with Access-Control-Allow-Credentials: true. This permits malicious third-party websites to perform authenticated cross-origin requests against the Eramba API, including endpoints like /system-api/login and /system-api/user/me. The response includes sensitive user session data (ID, name, email, access groups), which is accessible to the attacker's JavaScript. This flaw enables full session hijack and data exfiltration without user interaction. Eramba versions 3.23.3 and earlier were tested and appear unaffected. The vulnerability is present in default installations, requiring no custom configuration.

EPSS

Процентиль: 10%
0.00034
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-942