CVE-2025-41099

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the list of permissions using unauthorised internal identifiers.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Sep 2025, 11:37

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-30 11:37

Updated : 2025-10-02 19:12


NVD link : CVE-2025-41099

Mitre link : CVE-2025-41099

CVE.ORG link : CVE-2025-41099


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key