CVE 6.9 MEDIUM

Convercent Whistleblowing Platform Unauthenticated GetLegalEntity Endpoint Enables Customer Enumeration_CVE-2025-34411

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

The Convercent Whistleblowing Platform operated by EQS Group exposes an unauthenticated API endpoint at /GetLegalEntity that returns internal customer legal-entity names based on a supplied searchText fragment. A remote unauthenticated attacker can query the endpoint using common legal-suffix terms to enumerate Convercent tenants, identifying organizations using the platform. This disclosure can facilitate targeted phishing, extortion, or other attacks against whistleblowing programs and reveals sensitive business relationships and compliance infrastructure.

Basic Information

ID CVE-2025-34411
Source VulnCheck
Published Dec 15, 2025 at 14:43

Affected Product

Vendor EQS Group GmbH
Product Convercent Whistleblowing Platform
Affected Versions EQS Group GmbH Convercent Whistleblowing Platform 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.