Description

An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.

INFO

Published Date :

2025-03-06T00:00:00.000Z

Last Modified :

2025-03-07T19:45:40.092Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-25497 vulnerability.

No data.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact