CVE-2025-41358

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-12-10 12:16

Updated : 2025-12-12 15:18


NVD link : CVE-2025-41358

Mitre link : CVE-2025-41358

CVE.ORG link : CVE-2025-41358


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key