Vulnerability Details CVE-2025-27893
In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.3%
CVSS Severity
CVSS v3 Score 1.8
Products affected by CVE-2025-27893
-
cpe:2.3:a:archerirm:archer:6.10.0.3
-
cpe:2.3:a:archerirm:archer:6.11.0.4
-
cpe:2.3:a:archerirm:archer:6.12.0.0
-
cpe:2.3:a:archerirm:archer:6.12.0.6
-
cpe:2.3:a:archerirm:archer:6.12.0.6.1
-
cpe:2.3:a:archerirm:archer:6.13.0
-
cpe:2.3:a:archerirm:archer:6.13.0.1
-
cpe:2.3:a:archerirm:archer:6.13.0.2
-
cpe:2.3:a:archerirm:archer:6.13.0.2.2
-
cpe:2.3:a:archerirm:archer:6.13.0.3
-
cpe:2.3:a:archerirm:archer:6.13.0.3.1
-
cpe:2.3:a:archerirm:archer:6.13.0.4
-
cpe:2.3:a:archerirm:archer:6.14.0
-
cpe:2.3:a:archerirm:archer:6.14.0.1.2
-
cpe:2.3:a:archerirm:archer:6.14.0.2
-
cpe:2.3:a:archerirm:archer:6.14.0.2.1
-
cpe:2.3:a:archerirm:archer:6.14.0.2.2
-
cpe:2.3:a:archerirm:archer:6.14.0.3
-
cpe:2.3:a:archerirm:archer:6.14.0.4
-
cpe:2.3:a:archerirm:archer:6.3.0.0
-
cpe:2.3:a:archerirm:archer:6.8.0.0
-
cpe:2.3:a:archerirm:archer:6.9.3.4