CVE 7.1 HIGH

Insecure Direct Object Reference in GPS BOLD Workplanner_CVE-2025-41092

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user toย access to time records details using unauthorised internal identifiers.

Basic Information

ID CVE-2025-41092
Source INCIBE
Published Sep 30, 2025 at 11:12

Affected Product

Vendor GLOBAL PLANNING SOLUTIONS S.L (GPS)
Product BOLD Workplanner
Version 2.5.24
Affected Versions GLOBAL PLANNING SOLUTIONS S.L (GPS) BOLD Workplanner 2.5.24

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.