Home
CRITICAL: 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:N/RE:M/U:RedDefault status
unaffected
Any version
affected
Description
In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version
References
karatemuffin.it/data/2025_06_07_CVE-2024-55585_update.json
media.ccc.de/...-breit-eingesetzten-einsatzmanagmentsystems-