Insecure Direct Object Reference Vulnerability in BOLD Workplanner by BOLD
CVE-2025-41091

7.1HIGH

What is CVE-2025-41091?

The BOLD Workplanner contains an Insecure Direct Object Reference (IDOR) vulnerability affecting versions prior to 2.5.25. This flaw results from insufficient validation of user inputs, which could enable an authenticated user to manipulate internal identifiers to gain unauthorized access to sensitive calendar details. Proper input validation mechanisms must be applied to mitigate the risk posed by this vulnerability.

Affected Version(s)

BOLD Workplanner 2.5.24

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ángel Gonzålez
.
CVE-2025-41091 : Insecure Direct Object Reference Vulnerability in BOLD Workplanner by BOLD