CVE-2025-65900
04.12.2025, 22:15
Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.Enginsight
| Vendor | Product | Version |
|---|---|---|
| difuse | kalmia | 0.2.0 |
𝑥
= Vulnerable software versions