A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'.
Advisories

No advisories yet.

Fixes

Solution

The reported vulnerability has been fixed by the CanalDenuncia.app team in version 4.4.8.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Canaldenuncia canaldenuncia.app
CPEs cpe:2.3:a:canaldenuncia:canaldenuncia.app:*:*:*:*:*:*:*:*
Vendors & Products Canaldenuncia canaldenuncia.app
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 05 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Canaldenuncia
Canaldenuncia canaldenuncia App
Vendors & Products Canaldenuncia
Canaldenuncia canaldenuncia App

Tue, 04 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 13:30:00 +0000

Type Values Removed Values Added
Description A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'.
Title Missing Authorization vulnerability in CanalDenuncia.app
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-11-04T15:56:59.396Z

Reserved: 2025-04-16T09:57:02.393Z

Link: CVE-2025-41339

cve-icon Vulnrichment

Updated: 2025-11-04T15:56:54.144Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-04T14:15:35.817

Modified: 2025-11-05T17:03:30.027

Link: CVE-2025-41339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-05T10:47:35Z