Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in a controlled manner. This request has an “Origin” header that identifies the domain making the initial request and defines the protocol between a browser and a server to see if the request is allowed. An attacker can exploit this and potentially perform privileged actions and access confidential information when Access-Control-Allow-Credentials is enabled.

Project Subscriptions

Vendors Products
Hiberus Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution has been reported at this time.


Workaround

No workaround given by the vendor.

History

Fri, 03 Oct 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Hiberus
Hiberus sintra
Vendors & Products Hiberus
Hiberus sintra

Thu, 02 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Oct 2025 12:30:00 +0000

Type Values Removed Values Added
Description Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in a controlled manner. This request has an “Origin” header that identifies the domain making the initial request and defines the protocol between a browser and a server to see if the request is allowed. An attacker can exploit this and potentially perform privileged actions and access confidential information when Access-Control-Allow-Credentials is enabled.
Title Cross-origin resource sharing (CORS) in Hiberus Sintra
Weaknesses CWE-942
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-10-02T15:52:28.607Z

Reserved: 2025-04-16T09:08:43.217Z

Link: CVE-2025-41010

cve-icon Vulnrichment

Updated: 2025-10-02T15:18:19.050Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-02T13:15:31.717

Modified: 2025-10-02T19:11:46.753

Link: CVE-2025-41010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-03T08:22:44Z

Weaknesses