Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-65925

EPSS 0.09% · P25
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-65925

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to be created without completing the intended email verification step. While unverified accounts could not access product functionality, the behavior bypassed intended verification controls and allowed unintended account creation. This could have enabled spam/fake account creation or resource usage impact. No data exposure or unauthorized access to existing accounts was reported.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Zeroheight 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Zeroheight是英国Zeroheight公司的一个设计系统管理平台。 Zeroheight 2025-06-13之前版本存在安全漏洞,该漏洞源于遗留用户创建API允许绕过电子邮件验证步骤创建账户,可能导致垃圾邮件或虚假账户创建。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-65925

#POC DescriptionSource LinkShenlong Link
1Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)https://github.com/Sneden/zeroheight-account-verification-bypass-CVE-2025-65925POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-65925

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-12-30 · 16 CVEs total

CVE-2025-152647.3 HIGHFeehiCMS TimThumb timthumb.php server-side request forgery
CVE-2025-153604.7 MEDIUMnewbee-mall-plus Product Information Edit UploadController.java upload unrestricted upload
CVE-2025-152443.7 LOWPHPEMS Purchase Request race condition
CVE-2025-152423.1 LOWPHPEMS Coupon race condition
CVE-2025-61557nixseparatedebuginfod 安全漏洞
CVE-2025-56332pangolin 安全漏洞
CVE-2025-50343MATIO 安全漏洞
CVE-2025-66823TrueConf Server 安全漏洞
CVE-2025-66835TrueConf Client 安全漏洞
CVE-2025-66824TrueConf Server 安全漏洞
CVE-2025-66848JD Cloud多款产品 安全漏洞
CVE-2025-66834TrueConf Server 安全漏洞
CVE-2025-66723inMusic Engine DJ 安全漏洞
CVE-2025-65409GNU Recutils 安全漏洞
CVE-2025-65411GNU Unrtf 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-65925

No comments yet


Leave a comment