CVE Vulnerabilities

CVE-2025-2595

Direct Request ('Forced Browsing')

Published: Apr 23, 2025 | Modified: Apr 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Potential Mitigations

References