CVE-2025-25241
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/02/2025
Last modified:
18/02/2025
Description
Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM