Description
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'.
Published: 2025-11-04
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The reported vulnerability has been fixed by the CanalDenuncia.app team in version 4.4.8.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Canaldenuncia canaldenuncia.app
CPEs cpe:2.3:a:canaldenuncia:canaldenuncia.app:*:*:*:*:*:*:*:*
Vendors & Products Canaldenuncia canaldenuncia.app
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 05 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Canaldenuncia
Canaldenuncia canaldenuncia App
Vendors & Products Canaldenuncia
Canaldenuncia canaldenuncia App

Tue, 04 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
Description A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'.
Title Missing Authorization vulnerability in CanalDenuncia.app
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Canaldenuncia Canaldenuncia.app Canaldenuncia App
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-11-04T18:51:57.285Z

Reserved: 2025-04-16T09:09:39.344Z

Link: CVE-2025-41113

cve-icon Vulnrichment

Updated: 2025-11-04T18:50:38.055Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-04T13:15:35.017

Modified: 2025-11-05T17:06:37.963

Link: CVE-2025-41113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-05T10:47:35Z

Weaknesses