CVE 5.3 MEDIUM

KL-001-2025-013: Xorux XorMon-NG Web Application Privilege Escalation to Administrator_CVE-2025-54765

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to import the appliance configuration, allowing an attacker to control the configuration of the appliance, to include granting themselves administrative level permissions.

Basic Information

ID CVE-2025-54765
Source KoreLogic
Published Jul 28, 2025 at 23:25
Modified Jul 29, 2025 at 13:30

Affected Product

Vendor Xorux
Product XorMon-NG
Version 1.8
Affected Versions Xorux XorMon-NG 1.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.