Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 3.4.2
affected
Description
2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation. This vulnerability can only be exploited after authenticating with administrator privileges.
Problem types
CWE-117: Improper Output Neutralization for Logs
Product status
Any version before 3.4.2
References
www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf