Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'. | |
| Title | Direct reference to insecure objects (IDOR) in CronosWeb from CronosWeb i2A | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-12-10T11:16:28.620Z
Updated: 2025-12-10T16:40:32.182Z
Reserved: 2025-04-16T09:57:04.870Z
Link: CVE-2025-41358
Updated: 2025-12-10T16:40:28.203Z
Status : Received
Published: 2025-12-10T12:16:21.517
Modified: 2025-12-10T12:16:21.517
Link: CVE-2025-41358
No data.