This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API request URL to gain unauthorized access to other user accounts.
CVE ID: CVE-2025-29997
CVSS Base Severity: HIGH
CVSS Base Score: 8.2
CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Vendor: Rising Technosoft
Product: CAP back office application
EPSS Score: 0.14% (probability of being exploited)
EPSS Percentile: 30.89% (scored less or equal to compared to others)
EPSS Date: 2025-04-11 (when was this score calculated)