216.73.217.22

CVE-2025-62516

· Published 27/10/2025 20:15 · Modified 27/10/2025 20:15

Labels: CVE-2025-62516 2025-10-27CVE-2025-62516CWE-200[email protected]

Essential information

Published
27/10/2025 20:15
Modified
27/10/2025 20:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Landlord Onboarding & Rental Signup introduces the landlord onboarding workflow and rental signup system for VivaTurbo Rentals & Property Services. In 2.0.0 and earlier, a vulnerability was identified in the TurboTenant property listing activation workflow that could allow unauthorized access to certain Stripe payment session data. This could potentially expose sensitive business metadata, including landlord dashboard sync details and tenant information. The issue affects the API endpoints handling the property listing activation, subscription metadata, and payment link generation.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
vivaturbo / rentals cpe:2.3:a:vivaturbo:rentals:*:*:*:*:*:*:*:*
turbo / tenant cpe:2.3:a:turbo:tenant:*:*:*:*:*:*:*:*

References