CVE-2025-41404
Severity CVSS v4.0:
MEDIUM
Type:
CWE-425
Direct Request ('Forced Browsing')
Publication date:
26/06/2025
Last modified:
26/06/2025
Description
Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM