CVE-2025-0744
an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/demos/embedai/pmt_cash_on_delivery/pay" endpoint.
Vendor
Product
CWE
Yayın Tarihi
2025-01-30 12:15:27
Güncelleme
2025-10-08 19:18:30
Source Identifier
cve-coordination@incibe.es
KEV Date Added
-