CVE-2025-36759
BaseFortify
Publication date: 2025-09-10
Last updated on: 2025-09-11
Assigner: Dutch Institute for Vulnerability Disclosure
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| solax | cloud | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SolaX Cloud allows an attacker to obtain sensitive information such as user email addresses and phone numbers by providing user names. The system suggests similar user accounts based on the input, which leads to leaking this sensitive data.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive personal information like email addresses and phone numbers. This can result in privacy breaches, targeted phishing attacks, identity theft, and other malicious activities against affected users.