CVE-2025-43947

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
22/04/2025
Last modified:
23/06/2025

Description

Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codemers:klims:*:*:*:*:*:*:*:* 1.6_dev (including)