6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guest user may register itself as a guest user.
Basic Information
ID
CVE-2025-54461
Source
jpcert
Published
Oct 16, 2025 at 08:55
Affected Product
Vendor
NEOJAPAN Inc.
Product
ChatLuck
Version
V6.6 R2.0 and earlier
Affected Versions
NEOJAPAN Inc. ChatLuck V6.6 R2.0 and earlier