{"id":72752,"date":"2025-10-31T13:45:35","date_gmt":"2025-10-31T10:15:35","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-11843-therefore-online-and-therefore-on-premises-contains-an-account-impersonation-issue-which-could-potentially-allow-the-attacker-to-access-all-the-stored-data\/"},"modified":"2025-10-31T13:45:35","modified_gmt":"2025-10-31T10:15:35","slug":"cve-2025-11843-therefore-online-and-therefore-on-premises-contains-an-account-impersonation-issue-which-could-potentially-allow-the-attacker-to-access-all-the-stored-data","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-11843-therefore-online-and-therefore-on-premises-contains-an-account-impersonation-issue-which-could-potentially-allow-the-attacker-to-access-all-the-stored-data\/","title":{"rendered":"CVE-2025-11843 &#8211; Therefore\u2122 Online and Therefore\u2122 On-Premises contains an account impersonation issue, which could potentially allow the attacker to access all the stored data"},"content":{"rendered":"<p>CVE ID : CVE-2025-11843<\/p>\n<p>Published :  Oct. 31, 2025, 10:15 a.m. | 1\u00a0hour, 11\u00a0minutes ago<\/p>\n<p>Description : Therefore Corporation GmbH has recently become aware that Therefore\u2122 Online and Therefore\u2122 On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API when connecting to the Therefore\u2122 Server. If the malicious user gains this impersonation user access, then it is possible for them to access the documents stored in Therefore\u2122. This impersonation is at application level (Therefore access level), not the operating system level.<\/p>\n<p>Severity: 8.8 | HIGH<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-11843 Published : Oct. 31, 2025, 10:15 a.m. | 1\u00a0hour, 11\u00a0minutes ago Description : Therefore Corporation GmbH has recently become aware that Therefore\u2122 Online and Therefore\u2122 On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-72752","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=72752"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72752\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=72752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=72752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=72752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}