← volver
CVE-2025-12613

CVE-2025-12613

CVSS 8.8 HIGHEPSS 0.3%CWE-88
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
10 nov 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject additional, unintended parameters. This could lead to a variety of malicious outcomes, such as bypassing security checks, altering data, or manipulating the application's behavior. **Note:** Following our established security policy, we attempted to contact the maintainer regarding this vulnerability, but haven't received a response.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Productos afectados
n/a · cloudinary

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →