CVE-2025-45156
BaseFortify
Publication date: 2025-07-18
Last updated on: 2025-10-17
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| splashin | splashin | 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in Splashin iOS v2.0 is that it does not enforce server-side interval restrictions for location updates for free-tier users. This means that free users can send location updates more frequently than intended because the server does not properly limit the update intervals.
How can this vulnerability impact me? :
This vulnerability could lead to increased server load or resource consumption since free-tier users can send location updates more frequently than expected. It may also affect the accuracy or reliability of location data management and could potentially be exploited to bypass usage limits.