CVE-2025-12874
Last modified
CVE-2025-12874 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Manager for Notes (Free/Busy Connector modules) allows HTTP Request Smuggling via the Content-Length-Transfer-Encoding (CL.TE) attack vector. This could allow an attacker to bypass access controls, poison web caches, hijack sessions, or trigger unintended internal requests. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Manager for Notes (Free/Busy Connector modules) allows HTTP Request Smuggling via the Content-Length-Transfer-Encoding (CL.TE) attack vector. This could allow an attacker to bypass access controls, poison web caches, hijack sessions, or trigger unintended internal requests. This issue affects Coexistence Manager for Notes 3.8.2045. Other versions may also be affected.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-12874?
How severe is CVE-2025-12874?
How do I fix CVE-2025-12874?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-12869The a+HRD developed by aEnrich has a Stored Cross-Site Scrip…4.8
- CVE-2025-1287The The Plus Addons for Elementor – Elementor Addons, Page T…5.4
- CVE-2025-12870The a+HRD developed by aEnrich has an Authentication Abuse v…9.8
- CVE-2025-12871The a+HRD developed by aEnrich has an Authentication Abuse v…9.8
- CVE-2025-12872The a+HRD and a+HCM developed by aEnrich has a Stored Cross-…5.4
- CVE-2025-12873A security flaw has been discovered in Campcodes School File…9.8
- CVE-2025-12875A weakness has been identified in mruby 3.4.0. This vulnerab…7.8
- CVE-2025-12876The Projectopia – WordPress Project Management plugin for Wo…5.3
- CVE-2025-12877The IDonate – Blood Donation, Request And Donor Management S…5.3
- CVE-2025-12878The FunnelKit – Funnel Builder for WooCommerce Checkout plug…6.4
- CVE-2025-12879The User Generator and Importer plugin for WordPress is vuln…8.8
- CVE-2025-1288The WOOEXIM WordPress plugin through 5.0.0 does not have CS…6.1
Are you affected by CVE-2025-12874?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
