CVE-2025-41685: SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user
Published Aug 19, 2025
·Updated
A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.
Affected Software
1 affected component
SMA Sunny Portal
Event History
Aug 19, 2025
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41685?
CVE-2025-41685 is categorized as a low-severity vulnerability.
2
What impact does CVE-2025-41685 have on users?
CVE-2025-41685 allows a low-privileged remote attacker to obtain the username of another registered Sunny Portal user.
3
How can CVE-2025-41685 be mitigated?
To mitigate CVE-2025-41685, it is recommended to implement stronger access controls and user verification mechanisms.
4
Which software is affected by CVE-2025-41685?
CVE-2025-41685 affects the SMA Sunny Portal.
5
How do I know if I am affected by CVE-2025-41685?
You are affected by CVE-2025-41685 if you are using a version of the SMA Sunny Portal where user email addresses can be queried.