CVE-2025-3113
Severity CVSS v4.0:
CRITICAL
Type:
CWE-284
Improper Access Control
Publication date:
17/04/2025
Last modified:
17/04/2025
Description
A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the application’s built-in Connector functionality to access Continuous Compliance’s internal database. This allows the user to explore the internal database schema and export its data, including the properties of Connecters and Rule Sets.
Impact
Base Score 4.0
9.00
Severity 4.0
CRITICAL



