CVE-2025-50579 describes a Cross-Origin Resource Sharing (CORS) misconfiguration in Nginx Proxy Manager v2.12.3, allowing unauthorized domains to access sensitive data like JWT tokens due to improper Origin header validation. This vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity that can lead to unauthorized information disclosure. Currently, there is no public exploit intelligence, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.12.3CPE matchmatch criteria | cpe:2.3:a:jc21:nginx_proxy_manager:2.12.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.