CVE-2025-27422 Information

Description

FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information secure password etc) but there are no other controls stopping them. This vulnerability is fixed in 1.4.3.

Reference

https://github.com/factionsecurity/faction/commit/0a6848d388d6dba1c81918cce2772b1e805cd3d6 https://github.com/factionsecurity/faction/security/advisories/GHSA-97cv-f342-v2jc

Share on: