Project Subscriptions
No advisories yet.
Solution
The reported vulnerability has been fixed by the CanalDenuncia.app team in version 4.4.8.
Workaround
No workaround given by the vendor.
Wed, 05 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canaldenuncia canaldenuncia.app
|
|
| CPEs | cpe:2.3:a:canaldenuncia:canaldenuncia.app:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Canaldenuncia canaldenuncia.app
|
|
| Metrics |
cvssV3_1
|
Wed, 05 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canaldenuncia
Canaldenuncia canaldenuncia App |
|
| Vendors & Products |
Canaldenuncia
Canaldenuncia canaldenuncia App |
Tue, 04 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' in '/backend/api/buscarUsuarioByDenuncia.php'. | |
| Title | Missing Authorization vulnerability in CanalDenuncia.app | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-04T15:25:52.763Z
Reserved: 2025-04-16T09:57:02.393Z
Link: CVE-2025-41341
Updated: 2025-11-04T15:25:42.462Z
Status : Analyzed
Published: 2025-11-04T14:15:36.133
Modified: 2025-11-05T17:03:15.010
Link: CVE-2025-41341
No data.
OpenCVE Enrichment
Updated: 2025-11-05T10:47:39Z