Insecure Direct Object Reference in BOLD Workplanner by BOLD
CVE-2025-41094
7.1HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-41094?
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in BOLD Workplanner versions prior to 2.5.25. This flaw arises from insufficient validation of user input, enabling authenticated users to gain unauthorized access to functional contract details through internal identifiers. This vulnerability poses a significant risk as it allows misuse of information and could lead to data exposure or manipulation without proper authorization.
Affected Version(s)
BOLD Workplanner 2.5.24