CVE-2025-3113

Severity CVSS v4.0:
CRITICAL
Type:
CWE-284 Improper Access Control
Publication date:
17/04/2025
Last modified:
17/04/2025

Description

A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the application’s built-in Connector functionality to access Continuous Compliance’s internal database. This allows the user to explore the internal database schema and export its data, including the properties of Connecters and Rule Sets.

References to Advisories, Solutions, and Tools