Metrics
Affected Vendors & Products
No advisories yet.
Solution
The manufacturer T-INNOVA assures that the vulnerability is not present in version DSuite 2025 v02.14.1115.
Workaround
No workaround given by the vendor.
Thu, 13 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorized resources by manipulating requests using the 'idUsuario' parameter in ‘/ajax/TInnova_v2/Formulario_Consentimiento/llamadaAjax/obtenerDatosConsentimientos’, which could lead to the exposure or alteration os confidential data. | |
| Title | Insecure Direct Object References (IDOR) in DeporSite of T-Innova DeporSite | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-13T13:57:22.144Z
Reserved: 2025-04-16T09:09:34.458Z
Link: CVE-2025-41069
Updated: 2025-11-13T13:57:18.974Z
Status : Received
Published: 2025-11-13T14:15:48.747
Modified: 2025-11-13T14:15:48.747
Link: CVE-2025-41069
No data.
OpenCVE Enrichment
No data.