关键漏洞信息 漏洞标题 Broken authentication in legacy iCal service allows unauthenticated access to meeting data 严重性 等级: Moderate (5.3/10) CVSS v3 基础指标: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Confidentiality: Low - Integrity: None - Availability: None 影响版本与修复版本 受影响版本: - SuiteCRM: 8.8.0, 7.14.6 已修复版本: - SuiteCRM: 8.8.1, 7.14.7 描述 摘要: - Broken authentication in legacy iCal service allows unauthenticated access to meeting data. Associated functionality allows enumeration of user details. 影响: - An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. 其他信息 CVE ID: CVE-2025-54786 弱点类型: - CWE-200 - CWE-284 - CWE-287 报告者: sec31uk