An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint includes IP address, userAgent and location of the user that visited the web page.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Thesamur
Thesamur embedai |
|
CPEs | cpe:2.3:a:thesamur:embedai:*:*:*:*:*:*:*:* | |
Vendors & Products |
Thesamur
Thesamur embedai |
Tue, 18 Feb 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |
Thu, 30 Jan 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
Metrics |
ssvc
|
Thu, 30 Jan 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint includes IP address, userAgent and location of the user that visited the web page. | |
Title | Improper Access Control vulnerability in EmbedAI | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-02-18T19:03:35.811Z
Reserved: 2025-01-27T12:21:49.705Z
Link: CVE-2025-0743

Updated: 2025-01-30T13:48:02.231Z

Status : Analyzed
Published: 2025-01-30T12:15:27.707
Modified: 2025-10-08T19:18:43.227
Link: CVE-2025-0743

No data.