This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grupo Castilla
Grupo Castilla epsilon Rh |
|
| Vendors & Products |
Grupo Castilla
Grupo Castilla epsilon Rh |
Wed, 29 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed. | |
| Title | Unprotected access to parts of the application in Epsilon RH by Grupo Castilla | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-10-29T10:51:36.915Z
Updated: 2025-10-29T13:33:58.079Z
Reserved: 2025-10-29T10:23:47.181Z
Link: CVE-2025-12461
Updated: 2025-10-29T13:33:51.891Z
Status : Awaiting Analysis
Published: 2025-10-29T11:15:43.883
Modified: 2025-10-30T15:03:13.440
Link: CVE-2025-12461
No data.
ReportizFlow