We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-47817



Description

In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.

Reserved 2025-05-10 | Published 2025-05-10 | Updated 2025-05-12 | Assigner mitre


HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-472 External Control of Assumed-Immutable Web Parameter

Product status

Default status
unknown

Any version
affected

References

github.com/bluewave-labs/Checkmate/pull/2161

github.com/...ckmate/security/advisories/GHSA-rq7r-p9cq-5q4f

github.com/...ommit/b387ebaae96fc3a23b090a8baea7a9ebaa70f052

cve.org (CVE-2025-47817)

nvd.nist.gov (CVE-2025-47817)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-47817

Support options

Helpdesk Chat, Email, Knowledgebase