Project Subscriptions
No advisories yet.
Solution
The reported vulnerability has been fixed by the CanalDenuncia.app team in version 4.4.8.
Workaround
No workaround given by the vendor.
Wed, 05 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canaldenuncia canaldenuncia.app
|
|
| CPEs | cpe:2.3:a:canaldenuncia:canaldenuncia.app:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Canaldenuncia canaldenuncia.app
|
|
| Metrics |
cvssV3_1
|
Wed, 05 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canaldenuncia
Canaldenuncia canaldenuncia App |
|
| Vendors & Products |
Canaldenuncia
Canaldenuncia canaldenuncia App |
Tue, 04 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarTestigoByIdDenunciaUsuario.php'. | |
| Title | Missing Authorization vulnerability in CanalDenuncia.app | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-04T16:34:56.240Z
Reserved: 2025-04-16T09:57:02.393Z
Link: CVE-2025-41338
Updated: 2025-11-04T16:30:12.586Z
Status : Analyzed
Published: 2025-11-04T14:15:35.670
Modified: 2025-11-05T17:03:36.127
Link: CVE-2025-41338
No data.
OpenCVE Enrichment
Updated: 2025-11-05T10:47:32Z