CVE-2025-2280
13.03.2025, 13:15
Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.Enginsight
| Vendor | Product | Version |
|---|---|---|
| devolutions | devolutions_server | 𝑥 < 2024.3.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration