CVE 8.6 HIGH

Multiple vulnerabilities in Viafirma products_CVE-2025-41077

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

AI Analysis

IDOR vulnerability allowing authenticated users to list, access, and modify user data, potentially leading to administrative access

Basic Information

ID CVE-2025-41077
Source INCIBE
Published Jan 12, 2026 at 14:54
Modified Jan 12, 2026 at 16:23

Affected Product

Vendor Viafirma
Product Inbox
Version v4.5.13
Affected Versions Viafirma Inbox v4.5.13

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor Viafirma
Product Inbox
Version v4.5.13

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.