Executive brief
Beamsec PhishPro, a platform used for phishing simulation and security awareness training, contains a vulnerability that allows for the abuse of administrative privileges. An attacker with low-level access could exploit this flaw to perform actions they are not authorized to do, potentially leading to full system compromise or unauthorized access to sensitive training and employee data. This could disrupt security operations and expose internal organizational details.
Technical details
A vulnerability classified as CWE-648 (Incorrect Use of Privileged APIs) exists in Beamsec PhishPro before version 7.5.4.2. The flaw allows an authenticated user with low privileges to interact with sensitive APIs in a manner that grants them unauthorized administrative capabilities. The attack vector is network-based and requires low privileges (PR:L) but no user interaction. Successful exploitation can lead to a total loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to upgrade to version 7.5.4.2 or later to mitigate this risk.
Affected products
- Beamsec PhishPro before 7.5.4.2
Timeline
- 2025-07-28: advisory: Initial disclosure by TR-CERT (USOM)
- 2025-07-28: disclosed: CVE-2025-5997 published