We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-45237



Description

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

Reserved 2025-04-22 | Published 2025-05-05 | Updated 2025-05-06 | Assigner mitre

References

github.com/86dbs/dbsyncer

gist.github.com/chao112122/11cd0cc46f0c806856f375f9f3f410c6

cve.org (CVE-2025-45237)

nvd.nist.gov (CVE-2025-45237)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-45237

Support options

Helpdesk Chat, Email, Knowledgebase