Vulnerability Description
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibexa | Ez Platform | >= 2.0.0, <= 2.5.32 |
Related Weaknesses (CWE)
References
- https://gist.github.com/zywsec/a2bd04864895c8fd6d73dcf14a1f7607Third Party Advisory
FAQ
What is CVE-2025-70363?
CVE-2025-70363 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.
How severe is CVE-2025-70363?
CVE-2025-70363 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-70363?
Check the references section above for vendor advisories and patch information. Affected products include: Ibexa Ez Platform.