CVE-2024-55585 Information
Jun 08, 2025
cve
Description
In the moPS App through 1.8.618 all users can access administrative API endpoints without additional authentication resulting in unrestricted read and write access as demonstrated by /api/v1/users/resetpassword.
Reference
https://karatemuffin.it/data/2025_06_07_CVE-2024-55585_update.json https://media.ccc.de/v/glt25-504-safety-ja-security-nein-analyse-eines-breit-eingesetzten-einsatzmanagmentsystems- https://mops.eu
Share on: