CVE-2025-2202

MEDIUM

Innovación y Cualificación Plugin - Info Disclosure

Title source: llm
STIX 2.1

Description

Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email.

Scores

CVSS v4 6.9
EPSS 0.0034
EPSS Percentile 25.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
Innovación y Cualificación/ajax.php plugin all versions
Published Mar 17, 2025
Tracked Since Feb 18, 2026