Authorization Bypass in CanalDenuncia.app
CVE-2025-41341
8.7HIGH
What is CVE-2025-41341?
An authorization bypass vulnerability has been identified in CanalDenuncia.app, permitting unauthorized access to sensitive user information. By manipulating the request parameters 'id_denuncia' and 'seguro' in the endpoint '/backend/api/buscarUsuarioByDenuncia.php', attackers can potentially access the data of other users, posing a significant risk to the privacy and security of the platform's user base.
Affected Version(s)
CanalDenuncia.app 0 < 4.4.8
