CVE-2025-30352
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to filter items based on fields they do not have permission to view. This allows the enumeration of unknown field contents. The searchable columns (numbers & strings) are not checked against permissions when injecting the `where` clauses for applying the search query. This leads to the possibility of enumerating those un-permitted fields. Version 11.5.0 fixes the issue.
- Affected products
- Directus
- Monospace Directus
- < 11.5.0, 9.0.0
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.4% (29th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2025-03-26
CVE-2025-30352 at NVD
1 known exploit for CVE-2025-30352
Proof-of-concept code and exploit modules indexed by Sploitus