CVE-2025-1395
Information Disclosure via Error Messages in HeyGarson Application
Publication date: 2026-01-30
Last updated on: 2026-01-30
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| codriapp_innovation_and_software_technologies_inc | heygarson | to 30012026 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the generation of error messages that contain sensitive information in the HeyGarson application by Codriapp Innovation and Software Technologies Inc. It allows attackers to perform fuzzing for application mapping, potentially revealing internal details about the application.
How can this vulnerability impact me? :
The vulnerability can lead to exposure of sensitive information through error messages, which attackers can use to map the application and identify further weaknesses. This can increase the risk of targeted attacks and compromise of confidentiality.