CVE-2025-65900

MEDIUM

Kalmia CMS <0.2.0 - Info Disclosure

Title source: llm

Description

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.

Exploits (1)

nomisec WORKING POC
by Noxurge · poc
https://github.com/Noxurge/CVE-2025-65900

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 12.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-863
Status published
Products (1)
difuse/kalmia 0.2.0
Published Dec 04, 2025
Tracked Since Feb 18, 2026