Insecure Direct Object Reference in BOLD Workplanner by BOLD
CVE-2025-41095

7.1HIGH

What is CVE-2025-41095?

An Insecure Direct Object Reference (IDOR) vulnerability exists in BOLD Workplanner prior to version 2.5.25. This issue arises from insufficient validation of user input, allowing authenticated users to exploit unauthorized internal identifiers. As a result, attackers can gain access to sensitive planning counter details, potentially leading to unauthorized data exposure and privacy breaches.

Affected Version(s)

BOLD Workplanner 2.5.24

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ángel Gonzålez
.