MEDIUM🇵🇱 Wersja polska

CVE-2025-58580

CVSS 6.5v3.1pub. 2025-10-06upd. 2026-01-27

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
  • Sick Enterprise Analytics

    APP
    Sick
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-49184HIGH7.5same product

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...

CVE-2025-58579MEDIUM5.3same product

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint...

CVE-2025-58581MEDIUM4.3same product

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class...

CVE-2025-58582MEDIUM5.3same product

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST r...

CVE-2025-58583MEDIUM5.3same product

The application provides access to a login protected H2 database for caching purposes. The username...