Insecure Direct Object Reference in Benner Connecta Affects Remote Access
CVE-2025-1645

5.3MEDIUM

Key Information:

Vendor
Benner
Status
Connecta
Vendor
CVE Published:
25 February 2025

Summary

A vulnerability exists in Benner Connecta 1.0.5330 that allows for improper control of resource identifiers within the file /Usuarios/Usuario/EditarLogado/. This weakness can be exploited remotely, posing a significant risk of unauthorized access or manipulation of user resources. Despite early disclosure attempts to the vendor, there was no response, leaving systems potentially exposed to attack.

Affected Version(s)

Connecta 1.0.5330

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

y4g0 (VulDB User)
.