Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66911

Опубликовано: 19 дек. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:turms-im:turms:0.10.0-snapshot:*:*:*:*:*:*:*

EPSS

Процентиль: 10%
0.00035
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
github
около 2 месяцев назад

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.

EPSS

Процентиль: 10%
0.00035
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284