Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifiers.
CVSS
No CVSS.
References
Configurations
No configuration.
History
30 Sep 2025, 11:37
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-30 11:37
Updated : 2025-10-02 19:12
NVD link : CVE-2025-41096
Mitre link : CVE-2025-41096
CVE.ORG link : CVE-2025-41096
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key