Vulnerability Description
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with arbitrary pet IDs to retrieve sensitive information including pet details, member IDs, and avatar URLs without proper authorization checks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Petlibro | Petlibro | <= 1.7.31 |
Related Weaknesses (CWE)
References
- https://bobdahacker.com/blog/petlibroProduct
- https://www.vulncheck.com/advisories/petlibro-smart-pet-feeder-platform-through-Third Party Advisory
FAQ
What is CVE-2025-3660?
CVE-2025-3660 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership ...
How severe is CVE-2025-3660?
CVE-2025-3660 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3660?
Check the references section above for vendor advisories and patch information. Affected products include: Petlibro Petlibro.