CVE-2025-61117

HIGH

Senza: Keto & Fasting Android App <2.10.15 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an improper access control vulnerability. By exploiting insufficient checks in user data API endpoints, attackers can obtain authentication tokens and perform account takeover. Successful exploitation could result in unauthorized account access, privacy breaches, and misuse of the platform.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0030
EPSS Percentile 21.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Published Oct 30, 2025
Tracked Since Feb 18, 2026