vulnerability allows an attacker to access invoices of any user via
accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there
is no access control. The pdf filename can be obtained via OSINT,
insecure network traffic or brute force.
No analysis available yet.
Vendor Solution
The vulnerability has been fixed by DinoRANK team in the latest version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16323 | A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force. |
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 May 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force. | |
| Title | Missing Authorization in DinoRANK | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-28T13:24:05.823Z
Reserved: 2025-04-16T08:38:14.998Z
Link: CVE-2025-40673
Updated: 2025-05-28T13:23:56.981Z
Status : Deferred
Published: 2025-05-28T11:15:20.060
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-40673
No data.
OpenCVE Enrichment
No data.
EUVD