CVE-2025-12461
BaseFortify
Publication date: 2025-10-29
Last updated on: 2025-10-30
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| grupo_castilla | epsilon_rh | * |
| grupo_castilla | epsilon_rh | 3.03.36.0186 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows an attacker to access parts of the application that are not protected by any access control. Specifically, the attacker can access the path ββ¦/epsilonnet/License/About.aspxβ and obtain information about the license and configuration of the product, including which modules are installed.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive information about the product's license and configuration. This information could potentially be used by attackers to further exploit the system or understand its structure and capabilities.