9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.
AI Analysis
Privilege escalation vulnerability in Cerebrate before 1.30 via user-edit endpoint
Basic Information
ID
CVE-2025-66385
Source
mitre
Published
Nov 28, 2025 at 00:00
Modified
Nov 28, 2025 at 15:18
Affected Product
Vendor
cerebrate-project
Product
Cerebrate
Affected Versions
cerebrate-project Cerebrate 0
CWE Classification
AI Assessment
AI Score
9.4 / 10
AI Severity
Critical
Vendor
cerebrate-project
Product
Cerebrate
Version
< 1.30