Vulnerability Description
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dbsyncer Project | Dbsyncer | 2.0.6 |
Related Weaknesses (CWE)
References
- https://gist.github.com/chao112122/11cd0cc46f0c806856f375f9f3f410c6ExploitThird Party Advisory
- https://github.com/86dbs/dbsyncerProduct
FAQ
What is CVE-2025-45237?
CVE-2025-45237 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.
How severe is CVE-2025-45237?
CVE-2025-45237 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45237?
Check the references section above for vendor advisories and patch information. Affected products include: Dbsyncer Project Dbsyncer.