Authorization Flaw in CanalDenuncia.app by Canal Denuncia
CVE-2025-41335
8.7HIGH
What is CVE-2025-41335?
An authorization flaw in CanalDenuncia.app permits unauthorized access to sensitive user information. An attacker can exploit this vulnerability by manipulating the 'id' and 'id_sociedad' parameters in the POST request directed at '/api/buscarEmpresaById.php'. This security issue can lead to data breaches, impacting user privacy and trust.
Affected Version(s)
CanalDenuncia.app 0 < 4.4.8
