Critical9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

PT-2025-16: Disclosure of sensitive data in Booco

Error type:

  • CWE-200:Exposure of Sensitive Information to an Unauthorized Actor

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 9.3 (Critical)

Description:

The vulnerability was identified in Booco, versions 2.38, 2.39

The discovered vulnerability allows an unauthorized attacker to obtain administrator rights to the system, including access to all its data and functionality.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 14.05.2025

Recommendations:

  • Update to version 2.38.6 (for 2.38 branch), to 2.39.2 (for 2.39 branch)

  • Update to version 2.40.0 or higher

Additional information: Security advisory

Researcher: Vsevolod Dergunov (Positive Technologies)

Identifiers:

BDU:2025-06891

Vulnerable product:

Booco

Vulnerable versions:

2.38, 2.39