CVE-2025-12461

MEDIUM

Unprotected Path - Info Disclosure

Title source: llm
STIX 2.1

Description

This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed.

Scores

CVSS v4 6.9
EPSS 0.0006
EPSS Percentile 18.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (1)
Grupo Castilla/Epsilon RH 3.03.36.0185
Published Oct 29, 2025
Tracked Since Feb 18, 2026