CVE-2025-58580Medium· 6.5▾ SunlitAn API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.
enterprise_analyticsRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-58582Medium· 5.3If a user tries to login but the provided credentials are incorrect a log is created
CVE-2025-58583Medium· 5.3The application provides access to a login protected H2 database for caching purposes
CVE-2025-58581Medium· 4.3When an error occurs in the application a full stacktrace is provided to the user
CVE-2025-58578Low· 3.8A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request
CVE-2025-59463Medium· 4.3An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.
CVE-2025-59462Medium· 6.5An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.