CVE-2025-30352

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to filter items based on fields they do not have permission to view. This allows the enumeration of unknown field contents. The searchable columns (numbers & strings) are not checked against permissions when injecting the `where` clauses for applying the search query. This leads to the possibility of enumerating those un-permitted fields. Version 11.5.0 fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
GitHub_MCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
monospacedirectus
9.0.1 ≤
𝑥
< 11.5.0
monospacedirectus
9.0.0:alpha10
monospacedirectus
9.0.0:alpha11
monospacedirectus
9.0.0:alpha12
monospacedirectus
9.0.0:alpha13
monospacedirectus
9.0.0:alpha14
monospacedirectus
9.0.0:alpha15
monospacedirectus
9.0.0:alpha16
monospacedirectus
9.0.0:alpha17
monospacedirectus
9.0.0:alpha18
monospacedirectus
9.0.0:alpha19
monospacedirectus
9.0.0:alpha20
monospacedirectus
9.0.0:alpha21
monospacedirectus
9.0.0:alpha22
monospacedirectus
9.0.0:alpha23
monospacedirectus
9.0.0:alpha24
monospacedirectus
9.0.0:alpha25
monospacedirectus
9.0.0:alpha26
monospacedirectus
9.0.0:alpha27
monospacedirectus
9.0.0:alpha31
monospacedirectus
9.0.0:alpha32
monospacedirectus
9.0.0:alpha33
monospacedirectus
9.0.0:alpha34
monospacedirectus
9.0.0:alpha35
monospacedirectus
9.0.0:alpha36
monospacedirectus
9.0.0:alpha37
monospacedirectus
9.0.0:alpha38
monospacedirectus
9.0.0:alpha39
monospacedirectus
9.0.0:alpha4
monospacedirectus
9.0.0:alpha40
monospacedirectus
9.0.0:alpha41
monospacedirectus
9.0.0:alpha42
monospacedirectus
9.0.0:alpha5
monospacedirectus
9.0.0:alpha6
monospacedirectus
9.0.0:alpha7
monospacedirectus
9.0.0:alpha8
monospacedirectus
9.0.0:alpha9
monospacedirectus
9.0.0:beta0
monospacedirectus
9.0.0:beta1
monospacedirectus
9.0.0:beta10
monospacedirectus
9.0.0:beta11
monospacedirectus
9.0.0:beta12
monospacedirectus
9.0.0:beta13
monospacedirectus
9.0.0:beta14
monospacedirectus
9.0.0:beta2
monospacedirectus
9.0.0:beta3
monospacedirectus
9.0.0:beta4
monospacedirectus
9.0.0:beta5
monospacedirectus
9.0.0:beta7
monospacedirectus
9.0.0:beta8
monospacedirectus
9.0.0:beta9
monospacedirectus
9.0.0:rc0
monospacedirectus
9.0.0:rc1
monospacedirectus
9.0.0:rc10
monospacedirectus
9.0.0:rc100
monospacedirectus
9.0.0:rc101
monospacedirectus
9.0.0:rc11
monospacedirectus
9.0.0:rc12
monospacedirectus
9.0.0:rc13
monospacedirectus
9.0.0:rc14
monospacedirectus
9.0.0:rc15
monospacedirectus
9.0.0:rc17
monospacedirectus
9.0.0:rc18
monospacedirectus
9.0.0:rc19
monospacedirectus
9.0.0:rc2
monospacedirectus
9.0.0:rc20
monospacedirectus
9.0.0:rc21
monospacedirectus
9.0.0:rc22
monospacedirectus
9.0.0:rc23
monospacedirectus
9.0.0:rc24
monospacedirectus
9.0.0:rc25
monospacedirectus
9.0.0:rc26
monospacedirectus
9.0.0:rc27
monospacedirectus
9.0.0:rc28
monospacedirectus
9.0.0:rc29
monospacedirectus
9.0.0:rc3
monospacedirectus
9.0.0:rc30
monospacedirectus
9.0.0:rc31
monospacedirectus
9.0.0:rc32
monospacedirectus
9.0.0:rc33
monospacedirectus
9.0.0:rc34
monospacedirectus
9.0.0:rc35
monospacedirectus
9.0.0:rc36
monospacedirectus
9.0.0:rc37
monospacedirectus
9.0.0:rc38
monospacedirectus
9.0.0:rc39
monospacedirectus
9.0.0:rc4
monospacedirectus
9.0.0:rc40
monospacedirectus
9.0.0:rc41
monospacedirectus
9.0.0:rc42
monospacedirectus
9.0.0:rc43
monospacedirectus
9.0.0:rc44
monospacedirectus
9.0.0:rc45
monospacedirectus
9.0.0:rc46
monospacedirectus
9.0.0:rc47
monospacedirectus
9.0.0:rc48
monospacedirectus
9.0.0:rc49
monospacedirectus
9.0.0:rc5
monospacedirectus
9.0.0:rc50
monospacedirectus
9.0.0:rc51
monospacedirectus
9.0.0:rc52
monospacedirectus
9.0.0:rc53
monospacedirectus
9.0.0:rc54
monospacedirectus
9.0.0:rc55
monospacedirectus
9.0.0:rc56
monospacedirectus
9.0.0:rc57
monospacedirectus
9.0.0:rc58
monospacedirectus
9.0.0:rc59
monospacedirectus
9.0.0:rc6
monospacedirectus
9.0.0:rc60
monospacedirectus
9.0.0:rc61
monospacedirectus
9.0.0:rc62
monospacedirectus
9.0.0:rc63
monospacedirectus
9.0.0:rc64
monospacedirectus
9.0.0:rc65
monospacedirectus
9.0.0:rc66
monospacedirectus
9.0.0:rc67
monospacedirectus
9.0.0:rc68
monospacedirectus
9.0.0:rc69
monospacedirectus
9.0.0:rc7
monospacedirectus
9.0.0:rc70
monospacedirectus
9.0.0:rc71
monospacedirectus
9.0.0:rc72
monospacedirectus
9.0.0:rc73
monospacedirectus
9.0.0:rc74
monospacedirectus
9.0.0:rc75
monospacedirectus
9.0.0:rc76
monospacedirectus
9.0.0:rc77
monospacedirectus
9.0.0:rc78
monospacedirectus
9.0.0:rc79
monospacedirectus
9.0.0:rc8
monospacedirectus
9.0.0:rc80
monospacedirectus
9.0.0:rc81
monospacedirectus
9.0.0:rc82
monospacedirectus
9.0.0:rc83
monospacedirectus
9.0.0:rc84
monospacedirectus
9.0.0:rc85
monospacedirectus
9.0.0:rc86
monospacedirectus
9.0.0:rc87
monospacedirectus
9.0.0:rc88
monospacedirectus
9.0.0:rc89
monospacedirectus
9.0.0:rc9
monospacedirectus
9.0.0:rc90
monospacedirectus
9.0.0:rc91
monospacedirectus
9.0.0:rc92
monospacedirectus
9.0.0:rc93
monospacedirectus
9.0.0:rc94
monospacedirectus
9.0.0:rc95
monospacedirectus
9.0.0:rc96
monospacedirectus
9.0.0:rc97
monospacedirectus
9.0.0:rc98
monospacedirectus
9.0.0:rc99
𝑥
= Vulnerable software versions