CVE-2025-41358
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
10/12/2025
Last modified:
10/12/2025
Description
Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.
Impact
Base Score 4.0
8.30
Severity 4.0
HIGH



