Insecure Direct Object Reference in DM Corporative CMS by DM Acroweb
CVE-2025-40660
6.9MEDIUM
What is CVE-2025-40660?
An Insecure Direct Object Reference (IDOR) vulnerability exists in DM Corporative CMS, which could enable an attacker to manipulate specific parameters. By setting the option parameter to values such as 0, 1, or 2 within the admin area, unauthorized users may access restricted sections of the application. This issue emphasizes the necessity for secure coding practices to validate user inputs and restrict direct access to sensitive operations.
Affected Version(s)
DM Corporative CMS 0 < 2025.01