CVE-2025-0691
05.06.2025, 14:15
Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.Enginsight
Vendor | Product | Version |
---|---|---|
devolutions | devolutions_server | 𝑥 ≤ 2025.1.10.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration