CWE-612Base

Improper Authorization of Index Containing Sensitive Information

Draft in the CWE catalog · 11 CVEs mapped

11
CVEs mapped
6.9
Median CVSS
What it is

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Recent examples
8.7cvss
CVE-2019-25605

EquityPandit 1.0 Insecure Logging Information Disclosure

EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user account credentials.

HIGHno explanation yet
0%
epss
6.9cvss
CVE-2025-3660

Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.

MEDIUMno explanation yet
0%
epss
6.9cvss
CVE-2025-3654

Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to device hardware information by exploiting insecure API endpoints. Attackers can retrieve device serial numbers and MAC addresses through /device/devicePetRelation/getBoundDevices using pet IDs, enabling full device control without proper authorization checks.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-612
Abstraction
Base
Structure
Simple
Status
Draft
References (1)