CVE-2025-13250
BaseFortify
Publication date: 2025-11-16
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| datax-web_project | datax-web | to 2.1.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in WeiYe-Jing datax-web up to version 2.1.2, specifically in the Job Handler component's functions such as remove, update, pause, start, and triggerJob. It allows improper access control, meaning an attacker can manipulate these functions remotely without proper authorization.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to remotely manipulate job handling functions, potentially disrupting operations, modifying or triggering jobs without permission, which could lead to unauthorized actions and impact system integrity and availability.