Gliffy Broken Authentication Vulnerability

Vulnerability

A broken authentication vulnerability has been identified in Gliffy, affecting versions prior to 4.14.0-7. The issue arises from the application's password reset functionality, which does not properly authenticate users, potentially allowing unauthorized access or actions.

Impact

Exploitation of this vulnerability could lead to unauthorized access or actions within the application, bypassing normal authentication mechanisms.

Remediation

Users can upgrade to Gliffy version 4.14.0-7 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.