CVE-2025-58578Low· 3.8▾ SunlitA user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.
enterprise_analyticsRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-58582Medium· 5.3If a user tries to login but the provided credentials are incorrect a log is created
CVE-2025-58583Medium· 5.3The application provides access to a login protected H2 database for caching purposes
CVE-2025-58581Medium· 4.3When an error occurs in the application a full stacktrace is provided to the user
CVE-2025-58580Medium· 6.5An API endpoint allows arbitrary log entries to be created via POST request
CVE-2025-59459Medium· 5.5An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.
CVE-2025-59463Medium· 4.3An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.