Vulnerability Description
Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. This includes the actual token, although only the hashed token. This does not include any un-hashed authentication token as viewable. This issue has been patched in version 1.21.0. A workaround for this is not deemed viable as it would involve disabling token authentication. Users are encouraged to remove any authentication token that was created by one of the effected versions of Centurion ERP. Webmasters can ensure this occurs by removing all authentication tokens from the database.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nofusscomputing | Centurion Erp | >= 1.12.0, < 1.21.0 |
Related Weaknesses (CWE)
References
- https://github.com/nofusscomputing/centurion_erp/commit/332eb1075ad828e5c4c24caePatch
- https://github.com/nofusscomputing/centurion_erp/pull/974Issue Tracking
- https://github.com/nofusscomputing/centurion_erp/security/advisories/GHSA-x75j-cVendor Advisory
FAQ
What is CVE-2025-58156?
CVE-2025-58156 is a vulnerability with a CVSS score of 1.9 (LOW). Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. Thi...
How severe is CVE-2025-58156?
CVE-2025-58156 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-58156?
Check the references section above for vendor advisories and patch information. Affected products include: Nofusscomputing Centurion Erp.