CVE-2025-2201

MEDIUM

IcProgress Innovación y Cualificación - Info Disclosure

Title source: llm
STIX 2.1

Description

Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more.

Scores

CVSS v4 6.9
EPSS 0.0034
EPSS Percentile 25.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
Innovación y Cualificación/IcProgreso plugin all versions
Published Mar 17, 2025
Tracked Since Feb 18, 2026