CVE Feed

    Dashboard / CVE / CVE-2025-66911

    CVE-2025-66911

    Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.

    Published:Dec 19, 2025
    Last Modified:Jan 2, 2026
    EPS:Dec 19, 2025
    EPSS Score:0.0003
    CVSS Score:6.5

    Affected Products

    Vendor
    Turms
    Product
    Im-server
    Vendor
    Turms-im
    Product
    Turms

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High