CVE-2025-70614
CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17º percentile).
Vulnerabilità · 190 giorni fa
Una vulnerabilità in OpenCode OC Messaging e USSD Gateway 6.32.2 permette a un utente autenticato con privilegi bassi di accedere a SMS al di fuori del proprio tenant tramite un parametro identifier manipolato.
CVSS 8.1 HIGH: openCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the… EPSS 0.3% (17º percentile).
1 fonte che coprono questa storia
OpenCode Systems OC Messaging and Custom Messaging Gateway | CISA
OpenCode Systems OC Messaging and Custom Messaging Gateway Summary Successful exploitation of this vulnerability could allow an authenticated low-privileged user to gain access to SMS messages outside of their authorized tenant scope via a crafted company or tenant identifier…
Part of the PlainSec briefing for 2026-03-27