Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY ¡ Raised: 1359 CNY

100%

CVE-2025-0987 — AI Deep Analysis Summary

CVSS 9.9 ¡ Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: CVE-2025-0987 is a critical flaw in **CB Project CVLand**. It allows **authorization bypass** due to user-controlled keys.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: **CWE-639** (Authorization Bypass Through User-Controlled Key).…

Q3Who is affected? (Versions/Components)

📱 **Affected Product**: **CB Project CVLand** (Recruitment Mobile App by CB Project Ltd. Co.). <br>📅 **Versions**: **2.1.0** through **20251103**. <br>🌍 **Vendor**: Turkish company CB Project.

Q4What can hackers do? (Privileges/Data)

💀 **Attacker Actions**: <br>1️⃣ **Bypass Auth**: Gain unauthorized access without valid credentials. <br>2️⃣ **Parameter Injection**: Manipulate backend parameters.…

Q5Is exploitation threshold high? (Auth/Config)

🔑 **Exploitation Threshold**: <br>✅ **Network**: Remote (AV:N). <br>✅ **Complexity**: Low (AC:L). <br>⚠️ **Privileges**: Requires **Low Privileges** (PR:L) to initiate. <br>👁️ **UI**: No User Interaction needed (UI:N).

Q6Is there a public Exp? (PoC/Wild Exploitation)

🚫 **Public Exploit**: **No**. <br>📂 **PoCs**: None listed in current data. <br>⏳ **Status**: Theoretical risk based on CVSS analysis. No wild exploitation confirmed yet.

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: <br>1️⃣ Verify app version is **< 20251103**. <br>2️⃣ Audit API endpoints for **user-controlled key injection**. <br>3️⃣ Monitor logs for **unauthorized access patterns** or parameter anomalies.

Q8Is it fixed officially? (Patch/Mitigation)

🛠️ **Official Fix**: Patch released on **2025-11-03**. <br>📝 **Reference**: USOM Advisory (tr-25-0371). <br>✅ **Action**: Update to the latest version immediately to close the authorization bypass.

Q9What if no patch? (Workaround)

🚧 **No Patch Workaround**: <br>1️⃣ **Restrict Access**: Limit network access to the app backend. <br>2️⃣ **Input Validation**: Strictly sanitize and validate all key inputs.…

Q10Is it urgent? (Priority Suggestion)

🔥 **Urgency**: **HIGH**. <br>📊 **CVSS**: High severity (C:H, I:H). <br>⚡ **Priority**: Immediate patching required. The low exploitation complexity makes it a prime target for attackers.