CVE-2025-11580: PowerJob list authorization
A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11580?
CVE-2025-11580 is classified as a high severity vulnerability due to its potential for remote exploitation and the impact of missing authorization.
How do I fix CVE-2025-11580?
To fix CVE-2025-11580, you should upgrade PowerJob to version 5.1.3 or later, which addresses the identified vulnerability.
What are the potential consequences of exploiting CVE-2025-11580?
Exploiting CVE-2025-11580 can lead to unauthorized access to user data and functionality through the affected /user/list file.
Who is affected by CVE-2025-11580?
CVE-2025-11580 affects all versions of PowerJob up to and including 5.1.2.
Can CVE-2025-11580 be exploited remotely?
Yes, CVE-2025-11580 can be remotely exploited due to the nature of the flaw in the authorization handling.