CVE-2025-60427
BaseFortify
Publication date: 2025-10-21
Last updated on: 2025-10-22
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| libretime | libretime | 3.0.0-alpha.10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in LibreTime 3.0.0-alpha.10 and possibly earlier versions is a Broken Access Control issue where users with the DJ role can access analytics data through the Web UI and direct API calls. The backend fails to verify role-based permissions for analytics endpoints, allowing users with lower privileges to retrieve station-wide metrics that they should not have access to.
How can this vulnerability impact me? :
The impact of this vulnerability is information disclosure, where less privileged users (such as those with the DJ role) can access sensitive analytics data that should be restricted. This could lead to unauthorized access to station-wide metrics, potentially exposing operational or usage information that could be misused.