CVE-2025-70982: Critical severity SpringBlade SpringBlade vulnerability
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70982?
CVE-2025-70982 has been classified as a critical vulnerability due to its allowing unauthorized access to sensitive user data.
How do I fix CVE-2025-70982?
To fix CVE-2025-70982, update SpringBlade to the latest version where the importUser access control has been properly enforced.
Who is affected by CVE-2025-70982?
Users of SpringBlade v4.5.0 are affected by CVE-2025-70982 as it allows attackers with low-level privileges to exploit the vulnerability.
What is the impact of CVE-2025-70982?
The impact of CVE-2025-70982 includes potential unauthorized access and importation of sensitive user data by attackers.
Are there any known exploits for CVE-2025-70982?
Yes, there are known exploit scenarios for CVE-2025-70982 where attackers can leverage low-level privileges to access sensitive user information.