Description
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDenunciasById.php'.
Problem types
Product status
Any version before 4.4.8
Credits
David Utón Amaya (m3n0sd0n4ld)
References
www.incibe.es/...o/multiple-vulnerabilities-canaldenunciaapp