← Back to CVE List

CVE-2025-30280

Published: 2025-04-08T09:15Z
Last Modified: 2025-04-14T08:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), Mendix Runtime V10.18 (All versions < V10.18.5), Mendix Runtime V10.6 (All versions < V10.6.22), Mendix Runtime V8 (All versions), Mendix Runtime V9 (All versions < V9.24.34). Affected applications allow for entity enumeration due to distinguishable responses in certain client actions. This could allow an unauthenticated remote attacker to list all valid entities and attribute names of a Mendix Runtime-based application. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt