CVE-2025-7204

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2025
Last modified:
10/07/2025

Description

In ConnectWise PSA versions older than 2025.9, a<br /> vulnerability exists where authenticated users could gain access to sensitive<br /> user information. Specific API requests were found to return an overly verbose<br /> user object, which included encrypted password hashes for other users.<br /> Authenticated users could then retrieve these hashes. <br /> <br /> <br /> <br /> An<br /> attacker or privileged user could then use these exposed hashes to conduct<br /> offline brute-force or dictionary attacks. Such attacks could lead to<br /> credential compromise, allowing unauthorized access to accounts, and<br /> potentially privilege escalation within the system.