CVE-2025-27422

FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information, secure password, etc) but there are no other controls stopping them. This vulnerability is fixed in 1.4.3.
Configurations

No configuration.

History

03 Mar 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 17:15

Updated : 2025-03-03 17:15


NVD link : CVE-2025-27422

Mitre link : CVE-2025-27422

CVE.ORG link : CVE-2025-27422


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication