CWE-612: Improper Authorization of Index Containing Sensitive Information
The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.
11 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2019-25605 — EquityPandit 1.0 Insecure Logging Information Disclosure
- CVE-2025-3660 — Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint
- CVE-2025-3654 — Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint
- CVE-2025-3653 — Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint
- CVE-2025-57756 — Contao discloses sensitive information in the front end search index
Recently published
- CVE-2019-25605 — EquityPandit 1.0 Insecure Logging Information Disclosure
- CVE-2025-3660 — Petlibro Smart Pet Feeder Platform through 1.7.31 Broken Access Control via API endpoint
- CVE-2025-3654 — Petlibro Smart Pet Feeder Platform through 1.7.31 Information Disclosure via API endpoint
- CVE-2025-3653 — Petlibro Smart Pet Feeder through 1.7.31 Platform Improper Access Control via API endpoint
- CVE-2025-57756 — Contao discloses sensitive information in the front end search index