CVE-2025-45237

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
05/05/2025
Last modified:
16/06/2025

Description

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:86dbs:dbsyncer:2.0.6:*:*:*:*:*:*:*