Unprotected access to parts of the application in Epsilon RH by Grupo Castilla
Vulnerability Description
This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the product by knowing which modules are installed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12461
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Oscar Atienza
More from Grupo Castilla
View All →Affected Vendor
Grupo Castilla
View all reports →