CVE-2025-58578

⚪ Do wiadomości

Brak ograniczeń w API pozwala autoryzowanym użytkownikom na nieograniczone tworzenie kont.

CVSS
3.8
EPSS
0.3%
Exploit
none
Vendor
sick
Opis źródłowy (NVD)

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-10-06 07:15:33 UTC
Ostatnia modyfikacja (NVD)2026-10-09 10:10:00 UTC
Referencje