CVE-2025-40673

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
28/05/2025
Last modified:
28/05/2025

Description

A Missing Authorization vulnerability has been found in DinoRANK. This <br /> vulnerability allows an attacker to access invoices of any user via <br /> accessing endpoint &amp;#39;/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf&amp;#39; because there <br /> is no access control. The pdf filename can be obtained via OSINT, <br /> insecure network traffic or brute force.