{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-1642","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-02-24T17:22:14.270Z","datePublished":"2025-02-25T00:31:04.569Z","dateUpdated":"2025-02-25T14:38:09.789Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-02-25T00:31:04.569Z"},"title":"Benner ModernaNet GetImageMedico resource injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-99","lang":"en","description":"Improper Control of Resource Identifiers"}]}],"affected":[{"vendor":"Benner","product":"ModernaNet","versions":[{"version":"1.0","status":"affected"},{"version":"1.1","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects unknown code of the file /AGE0000700/GetImageMedico?fooId=1. The manipulation of the argument fooId leads to improper control of resource identifiers. The attack can be initiated remotely. Upgrading to version 1.1.1 is able to address this issue. It is recommended to upgrade the affected component."},{"lang":"de","value":"In Benner ModernaNet bis 1.1.0 wurde eine Schwachstelle ausgemacht. Sie wurde als kritisch eingestuft. Betroffen ist eine unbekannte Verarbeitung der Datei /AGE0000700/GetImageMedico?fooId=1. Dank der Manipulation des Arguments fooId mit unbekannten Daten kann eine improper control of resource identifiers-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Ein Aktualisieren auf die Version 1.1.1 vermag dieses Problem zu lösen. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N"}}],"timeline":[{"time":"2025-02-24T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-02-24T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-02-24T18:28:01.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"y4g0 (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.296692","name":"VDB-296692 | Benner ModernaNet GetImageMedico resource injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.296692","name":"VDB-296692 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.499877","name":"Submit #499877 | benner modernanet < 1.1.1 IDOR - Insecure Direct Object Reference","tags":["third-party-advisory"]},{"url":"https://github.com/yago3008/cves","tags":["related"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-02-25T14:06:28.666338Z","id":"CVE-2025-1642","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-02-25T14:38:09.789Z"}}]}}