First published: Thu Jan 16 2025(Updated: )
Missing Authorization vulnerability in Pravin Durugkar User Sync ActiveCampaign allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Sync ActiveCampaign: from n/a through 1.3.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ActiveCampaign User Sync ActiveCampaign | <=1.3.2 | |
WordPress User Sync ActiveCampaign | <=1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23778 is considered a medium severity vulnerability due to its potential impact on unauthorized access.
To fix CVE-2025-23778, update User Sync ActiveCampaign to the latest version beyond 1.3.2 which addresses the missing authorization issue.
CVE-2025-23778 affects users of User Sync ActiveCampaign versions up to and including 1.3.2.
CVE-2025-23778 is classified as a missing authorization vulnerability that can lead to improperly configured access control.
Yes, CVE-2025-23778 can potentially be exploited in a production environment if access control is not properly configured.