CVE-2025-8057
BaseFortify
Publication date: 2025-09-16
Last updated on: 2025-09-17
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| patika_global_technologies | humansuite | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |
| CWE-610 | The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere. |
| CWE-285 | The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Authorization Bypass issue in Patika Global Technologies HumanSuite before version 53.21.0. It involves improper authorization where an attacker can exploit trust in the client by controlling a key or reference to access resources in another sphere without proper permission.
How can this vulnerability impact me? :
The vulnerability can allow an attacker with limited privileges to bypass authorization controls and access sensitive information or resources that they should not have access to, potentially leading to data exposure or unauthorized actions within the system.