GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints allow an authenticated user to request arbitrary user IDs and receive sensitive account data for those users, including the stored password and the account's security question and answer. The exposed recovery data and encrypted password may be used to reset or take over the target account.
History

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Miles33
Miles33 gn4 Publishing System
Vendors & Products Miles33
Miles33 gn4 Publishing System

Mon, 27 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints allow an authenticated user to request arbitrary user IDs and receive sensitive account data for those users, including the stored password and the account's security question and answer. The exposed recovery data and encrypted password may be used to reset or take over the target account.
Title GN4 Publishing System Insecure Direct Object Reference (IDOR) Information Disclosure
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-27T15:23:13.831Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34293

cve-icon Vulnrichment

Updated: 2025-10-27T15:23:09.214Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-24T22:15:40.210

Modified: 2025-10-27T13:20:15.637

Link: CVE-2025-34293

cve-icon Redhat

No data.