ZeroHour

CVE-2025-2280

CVSS 3.1
8.1 high
EPSS
<1%p41
Published
()
Modified
Description

Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.

Vendors
devolutions
Products
devolutions server
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.