Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Fri, 28 Nov 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opencode Systems
Opencode Systems ussd Gateway |
|
| Vendors & Products |
Opencode Systems
Opencode Systems ussd Gateway |
Wed, 26 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-26T00:00:00.000Z
Updated: 2025-12-03T16:45:34.908Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65238
Updated: 2025-12-03T16:45:28.085Z
Status : Awaiting Analysis
Published: 2025-11-26T17:15:47.460
Modified: 2025-12-03T17:15:53.577
Link: CVE-2025-65238
No data.