9.6
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Description
In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be called by any user who has completed login authentication, and it returns the plaintext authentication Tokens of all users currently logged in to the system. As a result, ordinary users can obtain the administrator's authentication Token through this interface, thereby forging an administrator account, gaining the system's management permissions, and taking over the system.
AI Analysis
Information disclosure vulnerability due to improper permission verification in the token query interface
Basic Information
ID
CVE-2025-63691
Source
mitre
Published
Nov 7, 2025 at 00:00
Modified
Nov 7, 2025 at 18:49
Affected Product
Vendor
Pig Mesh
Product
Pig
Version
3.8.2 and below
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
Pig Mesh
Product
Pig
Version
3.8.2 and below