A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.
Advisories

No advisories yet.

Fixes

Solution

The reported vulnerability has been fixed by the CanalDenuncia.app team in version 4.4.8.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 13:30:00 +0000

Type Values Removed Values Added
Description A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.
Title Missing Authorization vulnerability in CanalDenuncia.app
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-11-04T18:27:43.720Z

Reserved: 2025-04-16T09:57:02.393Z

Link: CVE-2025-41335

cve-icon Vulnrichment

Updated: 2025-11-04T18:27:38.688Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-04T14:15:35.220

Modified: 2025-11-04T15:40:45.533

Link: CVE-2025-41335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.