A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/view/default/user_set.htm. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_2.md | Exploit |
https://vuldb.com/?ctiid.306314 | Permissions Required VDB Entry |
https://vuldb.com/?id.306314 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.557748 | Third Party Advisory VDB Entry |
https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_2.md | Exploit |
Configurations
History
12 May 2025, 19:06
Type | Values Removed | Values Added |
---|---|---|
First Time |
Lecms lecms
Lecms |
|
References | () https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_2.md - Exploit | |
References | () https://vuldb.com/?ctiid.306314 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.306314 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.557748 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:lecms:lecms:3.0.3:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo |
28 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/dtwin88/cve-md/blob/main/lecms%20V3.0.3/lecms_2.md - |
27 Apr 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-27 17:15
Updated : 2025-05-12 19:06
NVD link : CVE-2025-3978
Mitre link : CVE-2025-3978
CVE.ORG link : CVE-2025-3978
JSON object : View
Products Affected
lecms
- lecms
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo