CVE-2025-2321

CVSS v3 Score
6.3
Medium
CVSS v2 Score
6.5
Medium

Vulnerability Description

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file /api/mjkj-chat/cgform-api/addData/. The manipulation of the argument chatUserID leads to business logic errors. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:6.3(Medium)

In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This co...

CVSS:6.5(Medium)

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to g...

CVSS:6.5(Medium)

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by a business logic error in the placeOrder graphql mutation. An authenticated attacker can l...

CVSS:6.5(Medium)

Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

CVSS:6.5(Medium)

Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

CVSS:6.0(Medium)

Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.