Insecure Direct Object Reference Vulnerability in BOLD Workplanner by BOLD
CVE-2025-41091
7.1HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-41091?
The BOLD Workplanner contains an Insecure Direct Object Reference (IDOR) vulnerability affecting versions prior to 2.5.25. This flaw results from insufficient validation of user inputs, which could enable an authenticated user to manipulate internal identifiers to gain unauthorized access to sensitive calendar details. Proper input validation mechanisms must be applied to mitigate the risk posed by this vulnerability.
Affected Version(s)
BOLD Workplanner 2.5.24