CVE-2025-25767
21.02.2025, 19:15
A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mrcms | mrcms | 3.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration