Vulnerability Details CVE-2025-70363
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.5%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-70363
-
cpe:2.3:a:ibexa:ez_platform:2.0.0
-
cpe:2.3:a:ibexa:ez_platform:2.0.0.1
-
cpe:2.3:a:ibexa:ez_platform:2.0.0.2
-
cpe:2.3:a:ibexa:ez_platform:2.0.1
-
cpe:2.3:a:ibexa:ez_platform:2.0.2
-
cpe:2.3:a:ibexa:ez_platform:2.1.0
-
cpe:2.3:a:ibexa:ez_platform:2.1.1
-
cpe:2.3:a:ibexa:ez_platform:2.2.0
-
cpe:2.3:a:ibexa:ez_platform:2.2.1
-
cpe:2.3:a:ibexa:ez_platform:2.2.2
-
cpe:2.3:a:ibexa:ez_platform:2.2.3
-
cpe:2.3:a:ibexa:ez_platform:2.2.3.1
-
cpe:2.3:a:ibexa:ez_platform:2.3.0
-
cpe:2.3:a:ibexa:ez_platform:2.3.1
-
cpe:2.3:a:ibexa:ez_platform:2.3.2
-
cpe:2.3:a:ibexa:ez_platform:2.3.2.1
-
cpe:2.3:a:ibexa:ez_platform:2.3.2.2
-
cpe:2.3:a:ibexa:ez_platform:2.4.0
-
cpe:2.3:a:ibexa:ez_platform:2.4.1
-
cpe:2.3:a:ibexa:ez_platform:2.4.2
-
cpe:2.3:a:ibexa:ez_platform:2.5.0
-
cpe:2.3:a:ibexa:ez_platform:2.5.1
-
cpe:2.3:a:ibexa:ez_platform:2.5.10
-
cpe:2.3:a:ibexa:ez_platform:2.5.11
-
cpe:2.3:a:ibexa:ez_platform:2.5.12
-
cpe:2.3:a:ibexa:ez_platform:2.5.13
-
cpe:2.3:a:ibexa:ez_platform:2.5.14
-
cpe:2.3:a:ibexa:ez_platform:2.5.15
-
cpe:2.3:a:ibexa:ez_platform:2.5.16
-
cpe:2.3:a:ibexa:ez_platform:2.5.17
-
cpe:2.3:a:ibexa:ez_platform:2.5.18
-
cpe:2.3:a:ibexa:ez_platform:2.5.19
-
cpe:2.3:a:ibexa:ez_platform:2.5.2
-
cpe:2.3:a:ibexa:ez_platform:2.5.20
-
cpe:2.3:a:ibexa:ez_platform:2.5.21
-
cpe:2.3:a:ibexa:ez_platform:2.5.22
-
cpe:2.3:a:ibexa:ez_platform:2.5.23
-
cpe:2.3:a:ibexa:ez_platform:2.5.24
-
cpe:2.3:a:ibexa:ez_platform:2.5.24.1
-
cpe:2.3:a:ibexa:ez_platform:2.5.25
-
cpe:2.3:a:ibexa:ez_platform:2.5.26
-
cpe:2.3:a:ibexa:ez_platform:2.5.27
-
cpe:2.3:a:ibexa:ez_platform:2.5.28
-
cpe:2.3:a:ibexa:ez_platform:2.5.29
-
cpe:2.3:a:ibexa:ez_platform:2.5.3
-
cpe:2.3:a:ibexa:ez_platform:2.5.30
-
cpe:2.3:a:ibexa:ez_platform:2.5.31
-
cpe:2.3:a:ibexa:ez_platform:2.5.4
-
cpe:2.3:a:ibexa:ez_platform:2.5.5
-
cpe:2.3:a:ibexa:ez_platform:2.5.6
-
cpe:2.3:a:ibexa:ez_platform:2.5.7
-
cpe:2.3:a:ibexa:ez_platform:2.5.8
-
cpe:2.3:a:ibexa:ez_platform:2.5.9