CVE-2023-25780: Status Powerbpm
Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
Affected products
- Status Powerbpm: version 2.0 only
Published 2023-06-02. Last modified 2026-06-17.