CVE-2025-65900
Last modified
CVE-2025-65900 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Difuse | Kalmia | 0.2.0 |
References
- https://github.com/Noxurge/CVE-2025-65900/blob/main/README.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-65900?
How severe is CVE-2025-65900?
How do I fix CVE-2025-65900?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-65891A GPU device-ID validation flaw in OneFlow v0.9.0 allows att…7.5
- CVE-2025-65892Reflected Cross-Site Scripting (rXSS) in krpano before versi…6.1
- CVE-2025-65896SQL injection vulnerability in long2ice assyncmy thru 0.2.10…9.8
- CVE-2025-65897zdh_web is a data collection, processing, monitoring, schedu…8.8
- CVE-2025-65899Kalmia CMS version 0.2.0 contains a user enumeration vulnera…5.3
- CVE-2025-6590Exposure of Sensitive Information to an Unauthorized Actor v…4.6
- CVE-2025-6591Vulnerability in Wikimedia Foundation MediaWiki. This vulner…0
- CVE-2025-6592Vulnerability in Wikimedia Foundation AbuseFilter. This vuln…2.1
- CVE-2025-65922PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors h…4.3
- CVE-2025-65923A Stored Cross-Site Scripting (XSS) vulnerability was discov…5.4
- CVE-2025-65924ERPNext thru 15.88.1 does not sanitize or remove certain HTM…4.1
- CVE-2025-65925An issue was discovered in Zeroheight (SaaS) prior to 2025-0…6.5
Are you affected by CVE-2025-65900?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
