CVE-2025-27893 Details
Description
In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. NOTE: the Supplier analyzed the reported exploitation steps and found that, although the user can modify the immutable field, upon switching to View mode the field is reverted to its original value, without anything being saved to the database (and consequently there is no impact).
A vulnerability exists in Archer Platform versions 6 through 6.14.00202.10024, allowing authenticated users with record creation privileges to manipulate immutable fields, such as the creation date. This is achieved by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. The exploitation of this vulnerability leads to unauthorized changes in system-generated metadata, thereby compromising data integrity and potentially disrupting auditing, compliance, and security controls.
ArcherIRM should implement proper validation to prevent unauthorized modifications of system-generated metadata. Additionally, access to the 'Copy' function could be restricted for non-administrative users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/NastyCrow/CVE-2025-27893 | CISA-ADP | ExploitThird Party Advisory |
| https://archerirm.com | [email protected] | Product |
| https://github.com/NastyCrow/CVE-2025-27893 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-472 | External Control of Assumed-Immutable Web Parameter | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| archerirm archer | >= 6.0.0.0, <= 6.14.00202.10024 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 8, 2025 | CVE Modified | [email protected] |
| Jun 23, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | CVE Modified | CISA-ADP |
| Mar 11, 2025 | New CVE Received | [email protected] |