Insecure Direct Object Reference Vulnerability in BOLD Workplanner by BOLD
CVE-2025-41099
7.1HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-41099?
The BOLD Workplanner has been identified with an Insecure Direct Object Reference vulnerability due to insufficient validation of user inputs. This flaw allows authenticated users to exploit unauthorized internal identifiers, potentially exposing a detailed list of permissions they should not access. To mitigate this risk, it is crucial for users to upgrade to version 2.5.25 or above, where this issue has been addressed. Regular audits and updates can significantly enhance security and protect sensitive information from unauthorized access.
Affected Version(s)
BOLD Workplanner 2.5.24