First published: Thu Mar 13 2025(Updated: )
A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct Object Reference (IDOR) vulnerability in the Issuetrak audit component. The vulnerability enables unauthorized access to sensitive information, including user details, network and hardware information, installed programs, running processes, drives, and printers. Due to improper access controls, an attacker can retrieve audit data belonging to other users, potentially leading to unauthorized data exposure, privacy violations, and security risks.
Credit: b7efe717-a805-47cf-8e9a-921fca0ce0ce
Affected Software | Affected Version | How to fix |
---|---|---|
Issuetrak | <17.2.2 |
Update to issuetrak to version 17.3 and beyond.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2271 is classified as a moderate severity vulnerability due to its potential for unauthorized access to sensitive audit results.
To fix CVE-2025-2271, upgrade Issuetrak to version 17.2.3 or later where this vulnerability is addressed.
Users of Issuetrak version 17.2.2 and prior are affected by CVE-2025-2271.
CVE-2025-2271 can be exploited through an Insecure Direct Object Reference (IDOR) attack, allowing low-privileged users to access unauthorized data.
CVE-2025-2271 allows low-privileged users to access audit results of other users, potentially exposing sensitive information.