Логотип exploitDog
bind:CVE-2025-54599
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-54599

Количество 2

Количество 2

nvd логотип

CVE-2025-54599

5 месяцев назад

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root cause of the issue is SSO misconfiguration.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wgfp-jjc7-g8jv

5 месяцев назад

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root cause of the issue is SSO misconfiguration.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-54599

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root cause of the issue is SSO misconfiguration.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-wgfp-jjc7-g8jv

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root cause of the issue is SSO misconfiguration.

CVSS3: 7.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу