Authorization Flaw in CanalDenuncia.app Exposing User Data
CVE-2025-41340
8.7HIGH
What is CVE-2025-41340?
A lack of authorization vulnerability has been identified in CanalDenuncia.app, which enables unauthorized attackers to gain access to sensitive information of other users. By manipulating the POST request parameters 'id_tp_denuncia' and 'id_sociedad' while interacting with the '/backend/api/buscarTipoDenunciabyId.php' endpoint, attackers can retrieve data they are not permitted to view, potentially compromising user privacy and data security.
Affected Version(s)
CanalDenuncia.app 0 < 4.4.8
