Metrics
Affected Vendors & Products
No advisories yet.
Solution
The vulnerability has been fixed in CronosWeb version 25.01 (available since December 1, 2025).
Workaround
No workaround given by the vendor.
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cronosweb I2a
Cronosweb I2a cronosweb |
|
| Vendors & Products |
Cronosweb I2a
Cronosweb I2a cronosweb |
Wed, 10 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'. | |
| Title | Direct reference to insecure objects (IDOR) in CronosWeb from CronosWeb i2A | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-10T16:40:32.182Z
Reserved: 2025-04-16T09:57:04.870Z
Link: CVE-2025-41358
Updated: 2025-12-10T16:40:28.203Z
Status : Received
Published: 2025-12-10T12:16:21.517
Modified: 2025-12-10T12:16:21.517
Link: CVE-2025-41358
No data.
OpenCVE Enrichment
Updated: 2025-12-11T21:38:21Z