CVE-2025-32255: ERA404 Stafflist

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList stafflist allows Retrieve Embedded Sensitive Data.This issue affects StaffList: from n/a through <= 3.2.7.

Affected products

  • ERA404 Stafflist: up to and including 3.2.7

Published 2025-04-04. Last modified 2026-06-17.