CVE-2025-43947

Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codemers:klims:*:*:*:*:*:*:*:*

History

23 Jun 2025, 17:59

Type Values Removed Values Added
References () https://de.linkedin.com/company/codemers - () https://de.linkedin.com/company/codemers - Product
References () https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43947 - () https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2025-43947 - Exploit, Third Party Advisory
First Time Codemers
Codemers klims
CPE cpe:2.3:a:codemers:klims:*:*:*:*:*:*:*:*

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) Codemers KLIMS 1.6.DEV carece de un mecanismo de control de acceso adecuado, lo que permite que un usuario normal de KLIMS realice todas las acciones que un administrador puede realizar, como modificar la configuración, crear un usuario, cargar archivos, etc.

22 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

22 Apr 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 18:16

Updated : 2025-06-23 17:59


NVD link : CVE-2025-43947

Mitre link : CVE-2025-43947

CVE.ORG link : CVE-2025-43947


JSON object : View

Products Affected

codemers

  • klims
CWE
CWE-284

Improper Access Control