An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint includes IP address, userAgent and location of the user that visited the web page.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-embedai | Third Party Advisory |
Configurations
History
08 Oct 2025, 19:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:thesamur:embedai:*:*:*:*:*:*:*:* | |
References | () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-embedai - Third Party Advisory | |
First Time |
Thesamur
Thesamur embedai |
18 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE |
30 Jan 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 |
30 Jan 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-30 12:15
Updated : 2025-10-08 19:18
NVD link : CVE-2025-0743
Mitre link : CVE-2025-0743
CVE.ORG link : CVE-2025-0743
JSON object : View
Products Affected
thesamur
- embedai
CWE
CWE-284
Improper Access Control