Information disclosure in Localization Manager - CVE-2020-25025

 

Information disclosure in Localization Manager - CVE-2020-25025

Published: September 3, 2020


Vulnerability identifier: #VU46244
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25025
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a missing access check. A remote authenticated attacker can view and export data of translatable fields which are outside of the users access scope and gain unauthorized access to sensitive information on the system.


Affected software

Localization Manager

How to mitigate CVE-2020-25025

Install updates from vendor's website.

Localization Manager - addressed in versions 7.4.0, 8.7.0, 9.2.0

External References

Related Security Bulletins