Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 4.4.8
affected
Description
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarComentariosByDenuncia.php'.
Problem types
Product status
Any version before 4.4.8
Credits
David Utón Amaya (m3n0sd0n4ld)
References
www.incibe.es/...o/multiple-vulnerabilities-canaldenunciaapp
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.