CVE-2025-26138

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:systemic-rm:risk_value:*:*:*:*:*:*:*:*

History

01 Apr 2025, 20:37

Type Values Removed Values Added
References () https://github.com/Arakiba/CVEs/tree/main/CVE-2025-26138 - () https://github.com/Arakiba/CVEs/tree/main/CVE-2025-26138 - Third Party Advisory
CPE cpe:2.3:a:systemic-rm:risk_value:*:*:*:*:*:*:*:*
First Time Systemic-rm
Systemic-rm risk Value

18 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 17:15

Updated : 2025-04-01 20:37


NVD link : CVE-2025-26138

Mitre link : CVE-2025-26138


JSON object : View

Products Affected

systemic-rm

  • risk_value
CWE

No CWE.