A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.
References
| Link | Resource |
|---|---|
| https://flowus.cn/share/a6170a19-032b-462d-8bf9-06ab139f78ba | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-02-21 19:15
Updated : 2025-04-22 12:58
NVD link : CVE-2025-25767
Mitre link : CVE-2025-25767
CVE.ORG link : CVE-2025-25767
JSON object : View
Products Affected
mrcms
- mrcms
CWE
CWE-266
Incorrect Privilege Assignment
