CVE-2025-25767 | MRCMS 3.1.2 Request UserController.java privileges assignment (EUVD-2025-4477)
A vulnerability classified as critical was found in MRCMS 3.1.2. Affected by this vulnerability is an unknown functionality of the file /controller/UserController.java of the component Request Handler. The manipulation leads to incorrect privilege assignment.
This vulnerability is known as CVE-2025-25767. Access to the local network is required for this attack to succeed. There is no exploit available.