Junglewise Threat Intelligence

CVE-2025-0606: Logo Software Logo Cloud Authorization Bypass via User-Controlled Key

CVE-2025-0606 · Severity: medium · CVSS 6 · Published 2025-10-06

Technologies: Logo Software Inc. Logo Cloud. Vendors: Logo Software Inc..

Executive brief

Logo Cloud, a cloud-based business management platform, contains a security flaw that allows authorized users to access data or resources they are not permitted to see. By manipulating specific identifiers in web requests, a high-privileged user could bypass intended restrictions to view sensitive information or cause resource leaks. This could lead to unauthorized data exposure and potential operational disruptions within the cloud environment.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Logo Software Inc. Logo Cloud versions prior to 0.67. The flaw stems from insufficient validation of user-controlled keys, which allows an attacker to perform 'forceful browsing' to access unauthorized resources. While the attack requires high privileges (PR:H), it can be executed over the network without user interaction. Successful exploitation enables the attacker to bypass authorization checks, potentially leading to sensitive resource exposure and resource leaks. The issue is addressed in version 0.67.

Affected products

  • Logo Software Inc. Logo Cloud before 0.67

Timeline

  • 2025-10-06: disclosed
  • 2025-10-06: advisory

References