CVE-2025-58156
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-29

Last updated on: 2025-09-24

Assigner: GitHub, Inc.

Description
Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. This includes the actual token, although only the hashed token. This does not include any un-hashed authentication token as viewable. This issue has been patched in version 1.21.0. A workaround for this is not deemed viable as it would involve disabling token authentication. Users are encouraged to remove any authentication token that was created by one of the effected versions of Centurion ERP. Webmasters can ensure this occurs by removing all authentication tokens from the database.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-29
Last Modified
2025-09-24
Generated
2026-05-27
AI Q&A
2025-08-30
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
nofusscomputing centurion_erp From 1.12.0 (inc) to 1.21.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Centurion ERP versions 1.12.0 to before 1.21.0 allows an authenticated user to view all authentication token details stored in the database, including the hashed tokens. However, un-hashed tokens are not viewable. This exposure could potentially allow attackers with some level of access to gain information about authentication tokens. The issue has been fixed in version 1.21.0.


How can this vulnerability impact me? :

The vulnerability could allow an authenticated user to access hashed authentication tokens, which might increase the risk of token misuse or unauthorized access if the hashes are compromised or cracked. Although the impact is limited since only hashed tokens are exposed and the CVSS base score is low (1.9), it still poses a confidentiality risk to authentication credentials.


What immediate steps should I take to mitigate this vulnerability?

Upgrade Centurion ERP to version 1.21.0 or later where the issue is patched. Additionally, remove all authentication tokens created by affected versions (1.12.0 to before 1.21.0) from the database to prevent unauthorized access. Workarounds such as disabling token authentication are not viable.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart