CVE-2025-40773Low· 3.5▾ SunlitA vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an att…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request.
Successful exploitation allows an attacker to potentially manipulate data belonging to other users.
sipass_integrated < 3.00Upgrade past the affected range:
sipass_integrated 3.00Connected by shared product, vendor, weakness, or advisory.
CVE-2025-40774Medium· 4.4A vulnerability has been identified in SiPass integrated (All versions < V3.0)
CVE-2025-40772High· 7.4A vulnerability has been identified in SiPass integrated (All versions < V3.0)
CVE-2025-12288Medium· 4.3A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4
CVE-2025-12283Medium· 4.3A security flaw has been discovered in code-projects Client Details System 1.0
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)