Insecure Direct Object Reference in BOLD Workplanner by BOLD
CVE-2025-41095
7.1HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-41095?
An Insecure Direct Object Reference (IDOR) vulnerability exists in BOLD Workplanner prior to version 2.5.25. This issue arises from insufficient validation of user input, allowing authenticated users to exploit unauthorized internal identifiers. As a result, attackers can gain access to sensitive planning counter details, potentially leading to unauthorized data exposure and privacy breaches.
Affected Version(s)
BOLD Workplanner 2.5.24