Critical
Low
Medium
CVE-2025-34293
Overview
GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints allow an authenticated user to request arbitrary user IDs and receive sensitive account data for those users, including the s...
Critical
Low
Medium
No items found.