6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST request to the /autologin/ API endpoint.
AI Analysis
Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, allowing remote attackers to obtain a high-privilege JWT token via an empty HTTP POST request to the /autologin/ API endpoint.
Basic Information
ID
CVE-2025-51054
Published
Aug 6, 2025 at 21:15
CWE Classification
AI Assessment
AI Severity
Medium
Vendor
Vedo
Product
Vedo Suite
Version
2024.17