Description
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".
INFO
Published Date :
2025-01-30T11:13:35.543Z
Last Modified :
2025-02-18T19:04:32.016Z
Source :
INCIBE
AFFECTED PRODUCTS
The following products are affected by CVE-2025-0741 vulnerability.
| Vendors | Products |
|---|---|
| Thesamur |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-0741.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact