Authorization Bypass in CanalDenuncia.app
CVE-2025-41339
8.7HIGH
What is CVE-2025-41339?
An authorization bypass vulnerability exists in CanalDenuncia.app that allows attackers to exploit the 'id_sociedad' parameter via a POST request in the '/backend/api/buscarTipoDenuncia.php' endpoint. This flaw enables unauthorized users to access sensitive information belonging to other users, raising serious data privacy concerns.
Affected Version(s)
CanalDenuncia.app 0 < 4.4.8
