CVE-2025-10352: Missing Authorization vulnerability in Melis Platform
Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthenticated attacker to create an administrator account via a request to '/melis/MelisCore/ToolUser/addNewUser'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10352?
CVE-2025-10352 has a high severity rating due to the potential for unauthorized access via account creation.
How do I fix CVE-2025-10352?
To fix CVE-2025-10352, apply the latest security patch provided by Melis Technology for the Melis Platform.
What impact does CVE-2025-10352 have on the Melis Platform?
CVE-2025-10352 allows unauthenticated attackers to create administrator accounts, compromising the security of the Melis Platform.
Is CVE-2025-10352 easy to exploit?
Yes, exploiting CVE-2025-10352 requires only a simple request to a specific URL without authentication.
Are there any workarounds for CVE-2025-10352?
While there are no official workarounds, restricting access to the affected endpoint can help mitigate the risk until a fix is applied.