CVE-2025-3567

MEDIUM

Echo 4.2 - Incorrect Privilege Assignment in LoginTicketInterceptor

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, was found in veal98 小牛肉 Echo 开源社区系统 4.2. Affected is the function preHandle of the file src/main/java/com/greate/community/controller/interceptor/LoginTicketInterceptor.java of the component Ticket Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.304608
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.304608
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.549537

Scores

CVSS v3 4.3
EPSS 0.0028
EPSS Percentile 19.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (1)
veal98 小牛肉/Echo 开源社区系统 4.2
Published Apr 14, 2025
Tracked Since Feb 18, 2026