Insecure Direct Object Reference in BOLD Workplanner Affects Authenticated Users
CVE-2025-41093
7.1HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-41093?
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in BOLD Workplanner, allowing authenticated users to access sensitive contract details by exploiting a flaw in user input validation. This security issue affects versions of BOLD Workplanner prior to 2.5.25 and may lead to unauthorized insights into internal data through improper handling of internal identifiers.
Affected Version(s)
BOLD Workplanner 2.5.24