CVE-2025-26656

OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
Configurations

No configuration.

History

11 Mar 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 01:15

Updated : 2025-03-11 01:15


NVD link : CVE-2025-26656

Mitre link : CVE-2025-26656

CVE.ORG link : CVE-2025-26656


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization