CVE-2025-65238: Medium severity OpenCode Systems USSD Gateway OC vulnerability
Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65238?
CVE-2025-65238 is classified as a medium severity vulnerability due to its potential to expose sensitive user information.
How do I fix CVE-2025-65238?
To fix CVE-2025-65238, ensure proper access controls are implemented in the getSubUsersByProvider function to restrict unauthorized access.
Which versions of OpenCode Systems USSD Gateway OC are affected by CVE-2025-65238?
CVE-2025-65238 affects OpenCode Systems USSD Gateway OC Release 5 Version 6.13.11.
What type of attack can CVE-2025-65238 enable?
CVE-2025-65238 can enable attackers with low-level privileges to dump user records and access sensitive information.
Is user data at risk due to CVE-2025-65238?
Yes, CVE-2025-65238 poses a risk to user data as it allows unauthorized access to sensitive information.