CVE-2025-29557
BaseFortify
Publication date: 2025-07-31
Last updated on: 2025-07-31
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| exagrid | ex10 | 6.3 |
| exagrid | ex10 | 7.0.1.p08 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in ExaGrid EX10 versions 6.3 to 7.0.1.P08, where the MailConfiguration API endpoint has incorrect access control. Specifically, users with operator-level privileges can send an HTTP request to retrieve SMTP credentials, including plaintext passwords, which should not be accessible to them.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of SMTP credentials, including plaintext passwords, to users with operator-level privileges. This could allow attackers or unauthorized users to misuse email services, potentially leading to further compromise of the system or data leakage.