Home

Description

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.

PUBLISHED Reserved 2025-04-16 | Published 2025-06-10 | Updated 2025-06-10 | Assigner INCIBE




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

Product status

Default status
unaffected

Any version before 2025.01
affected

Credits

Oscar Atienza finder

References

www.incibe.es/...ulnerabilities-dm-corporative-cms-dmacroweb

cve.org (CVE-2025-40659)

nvd.nist.gov (CVE-2025-40659)

Download JSON