CVE 8.8 HIGH

Business Logic Error in Universal Software’s FlexCity/Kiosk_CVE-2025-14349

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Properly Constrained by ACLs, Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

AI Analysis

Privilege escalation vulnerability due to missing authentication for critical functions in FlexCity/Kiosk, allowing unauthorized access to constrained functionality.

Basic Information

ID CVE-2025-14349
Source TR-CERT
Published Feb 13, 2026 at 13:09
Modified Feb 13, 2026 at 13:11

Affected Product

Vendor Universal Software Inc.
Product FlexCity/Kiosk
Version 1.0
Affected Versions Universal Software Inc. FlexCity/Kiosk 1.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Universal Software Inc.
Product FlexCity/Kiosk
Version 1.0 before 1.0.36

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.