CVE 7.1 HIGH

Insecure direct object reference (IDOR) vulnerability in Sergestec’s Exito_CVE-2025-41020

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.

Basic Information

ID CVE-2025-41020
Source INCIBE
Published Oct 16, 2025 at 07:59

Affected Product

Vendor Sergestec
Product Exito
Version 8.0
Affected Versions Sergestec Exito 8.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.