Vulnerabilità ed exploit · Attacco ad app web

OpenCode Messaging permette accesso cross-tenant a SMS in 6.32.2

Una vulnerabilità in OpenCode OC Messaging e USSD Gateway 6.32.2 permette a un utente autenticato con privilegi bassi di accedere a SMS al di fuori del proprio tenant tramite un parametro identifier manipolato.

1 fonte · 26 mar

CVE-2025-70614

NVD KEV

CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: OpenCode Messaging permette accesso cross-tenant a SMS in 6.32.2

Altro da oggi