A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in missing authorization. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 22 Jan 2026 06:15:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:rymcu:forest:*:*:*:*:*:*:*:*

Tue, 11 Nov 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 18:45:00 +0900

Type Values Removed Values Added
First Time appeared Rymcu
Rymcu forest
Vendors & Products Rymcu
Rymcu forest

Mon, 10 Nov 2025 10:45:00 +0900

Type Values Removed Values Added
Description A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in missing authorization. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
Title rymcu forest UserDicController.java deleteDic authorization
Weaknesses CWE-862
CWE-863
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-11-10T17:07:57.578Z

Reserved: 2025-11-09T06:53:53.615Z

Link: CVE-2025-12925

cve-icon Vulnrichment

Updated: 2025-11-10T17:07:50.976Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-10T02:15:34.917

Modified: 2026-01-21T21:13:44.633

Link: CVE-2025-12925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-10T18:33:10Z

Weaknesses