CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-0614: Input validation vulnerability in Qualifio's Wheel of Fortune

5.3 CVSS

Description

Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper and lower case characters in order to access the application and win prizes as many times as wanted.

Classification

CVE ID: CVE-2025-0614

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

Affected Products

Vendor: Qualifio

Product: Wheel of fortune

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 12.86% (scored less or equal to compared to others)

EPSS Date: 2025-02-19 (when was this score calculated)

References

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-qualifios-wheel-fortune

Timeline