Description
Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search concealed/sensitive fields when they have read permissions. While actual values remain masked (`****`), successful matches can be detected through returned records, enabling enumeration attacks on sensitive data. Version 11.13.0 fixes the issue.
INFO
Published Date :
2025-11-13T21:29:44.649Z
Last Modified :
2025-11-13T21:39:43.765Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-64748 vulnerability.
| Vendors | Products |
|---|---|
| Directus |
|
| Monospace |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-64748.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact