CVE-2025-41404

Severity CVSS v4.0:
MEDIUM
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
26/06/2025
Last modified:
30/09/2025

Description

Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:irohasoft:iroha_board:*:*:*:*:*:*:*:* 0.10.13 (excluding)