{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-11025", "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21", "state": "PUBLISHED", "assignerShortName": "TR-CERT", "dateReserved": "2025-09-26T08:09:24.845Z", "datePublished": "2025-09-26T12:40:31.008Z", "dateUpdated": "2026-06-04T19:46:20.740Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21", "shortName": "TR-CERT", "dateUpdated": "2026-06-04T19:46:20.740Z" }, "title": "Information Disclosure in Vimeosoft Information Technologies' Vimesoft Corporate Messaging Platform", "datePublic": "2025-09-26T12:34:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-201", "description": "CWE-201 Insertion of Sensitive Information Into Sent Data", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-37", "descriptions": [ { "lang": "en", "value": "CAPEC-37 Retrieve Embedded Sensitive Data" } ] } ], "affected": [ { "vendor": "Vimesoft Information Technologies and Software Inc.", "product": "Vimesoft Corporate Messaging Platform", "versions": [ { "status": "affected", "version": "V1.3.0", "lessThan": "V2.0.0", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data.\n\nThis issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data.
This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0.
" } ] } ], "references": [ { "url": "https://www.usom.gov.tr/bildirim/tr-25-0300", "tags": [ "government-resource", "broken-link" ] }, { "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0300", "tags": [ "government-resource" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseSeverity": "MEDIUM", "baseScore": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" } } ], "credits": [ { "lang": "en", "value": "Berat AKŞİT", "type": "finder" }, { "lang": "en", "value": "Sencer KILIÇ", "type": "finder" }, { "lang": "en", "value": "Berat AKŞİT", "type": "reporter" } ], "source": { "defect": [ "TR-25-0300" ], "advisory": "TR-25-0300", "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 0.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2025-09-26T13:39:06.180229Z", "id": "CVE-2025-11025", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-09-26T13:39:22.861Z" } } ] } }