Home
HIGH: 8.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:NDefault status
unaffected
25.00 and 24.05.
affected
Description
Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
25.00 and 24.05.
Credits
Félix Sánchez Medina
References
www.incibe.es/...secure-objects-idor-cronosweb-cronosweb-i2a