Home

Description

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_archivo' in '/backend/api/verArchivo.php'.

PUBLISHED Reserved 2025-04-16 | Published 2025-11-04 | Updated 2025-11-04 | Assigner INCIBE




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version before 4.4.8
affected

Credits

David Utón Amaya (m3n0sd0n4ld) finder

References

www.incibe.es/...o/multiple-vulnerabilities-canaldenunciaapp

cve.org (CVE-2025-41344)

nvd.nist.gov (CVE-2025-41344)

Download JSON