2025-11-22 Daily Vulns
NEW:
| CVE | vendor-product | description | metric | Referenceurl | title | GithubURL | |
|---|---|---|---|---|---|---|---|
| CVE-2025-0504 | Black Duck - Black Duck SCA | Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should have be inaccessible. Exploitation does not grant full system control, but it may enable unauthorized changes to project configurations or access to system sensitive information. | CVSS4.0: 5.3 - MEDIUM CVSS3.1: 5.4 - MEDIUM | 0 | Exploitation: noneAutomatable: noTechnical Impact: partial | Black Duck SCA Project Privilege Escalation | github |
| CVE-2025-10054 | elextensions - ELEX WordPress HelpDesk & Customer Ticketing System | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘eh_crm_remove_agent’ function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove the role and capabilities of any user with an Administrator, WSDesk Supervisor, or WSDesk Agents role. | CVSS3.1: 5.3 - MEDIUM | 0 1 2 | Exploitation: noneAutomatable: yesTechnical Impact: partial | ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Role Removal | github |
| CVE-2025-10039 | elextensions - ELEX WordPress HelpDesk & Customer Ticketing System | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.9 via the ‘eh_crm_ticket_single_view_client’ due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of all support tickets. | CVSS3.1: 4.3 - MEDIUM | 0 1 2 | Exploitation: noneAutomatable: noTechnical Impact: partial | ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure Direct Object Reference via ‘eh_crm_ticket_single_view_client’ | github |
This post is licensed under CC BY 4.0 by the author.