CVE-2025-27422 Details
Description
FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information, secure password, etc) but there are no other controls stopping them. This vulnerability is fixed in 1.4.3.
An authentication bypass vulnerability has been identified in FACTION, a PenTesting report generation and collaboration framework, in versions prior to 1.4.3. This vulnerability allows attackers to register new users with admin privileges at any time, without authorization. While the registration request must adhere to certain validation rules, such as providing complete information and a secure password, there are no additional controls to prevent unauthorized user creation.
The 'Create User' endpoint should be disabled after the initial admin user is created, requiring new users to be added by an existing administrator.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 3, 2025CISA-ADP
Assessed Mar 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/factionsecurity/faction/commit/0a6848d388d6dba1c81918cce2772b1e805cd3d6 | [email protected] | Source CodeVendor |
| https://github.com/factionsecurity/faction/security/advisories/GHSA-97cv-f342-v2jc | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FACTION | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2025 | New CVE Received | [email protected] |
Volerion