Beveiligingsadvies

CVE-2025-41358

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-10 11:16:28
Laatst bijgewerkt 2025-12-10 16:40:32
Toegewezen door INCIBE
CVSS-score 8.3
Status PUBLISHED

Beschrijving

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.