Due to a missing authorization check, an attacker who is logged in to application can view/ delete ?My Overtime Requests? which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.
CVSS
No CVSS.
References
Configurations
No configuration.
History
11 Feb 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-11 01:15
Updated : 2025-02-18 18:15
NVD link : CVE-2025-25241
Mitre link : CVE-2025-25241
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization