Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-639 |
|
| Metrics |
cvssV3_1
|
Fri, 19 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-19T15:24:40.148Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66911
Updated: 2025-12-19T15:24:34.841Z
Status : Received
Published: 2025-12-19T15:15:56.900
Modified: 2025-12-19T16:15:58.910
Link: CVE-2025-66911
No data.
OpenCVE Enrichment
No data.