IDOR Vulnerability in DM Corporative CMS by DM Acroweb
CVE-2025-40659
6.9MEDIUM
What is CVE-2025-40659?
An Insecure Direct Object Reference (IDOR) vulnerability exists in DM Corporative CMS that permits attackers to gain unauthorized access to private administrative areas. By manipulating the 'option' parameter in the request to '/administer/selectionnode/framesSelectionNetworks.asp', an unauthorized user can access restricted content, potentially leading to data exposure or modification. This vulnerability poses a significant risk as it allows escalation of privileges without proper authentication.
Affected Version(s)
DM Corporative CMS 0 < 2025.01