First published: Fri May 16 2025(Updated: )
Missing Authorization vulnerability in Ashan Perera EventON allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EventON: from n/a through 2.4.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
EventON | <=2.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-48116 is classified as a missing authorization vulnerability affecting EventON versions up to 2.4.4.
To fix CVE-2025-48116, you should update the EventON plugin to the latest version that addresses this vulnerability.
CVE-2025-48116 affects websites using the EventON plugin by Ashan Perera, specifically those running versions from n/a up to 2.4.4.
The risks of CVE-2025-48116 include unauthorized access to restricted functionalities within the EventON plugin.
You can verify if your site is affected by CVE-2025-48116 by checking the version of the EventON plugin installed on your website.