Authorization Flaw in CanalDenuncia.app by CanalDenuncia
CVE-2025-41345
8.7HIGH
What is CVE-2025-41345?
A lack of authorization vulnerability exists in CanalDenuncia.app, which enables unauthorized access to sensitive user information. Attackers can exploit this flaw by sending a crafted POST request with 'id_denuncia' and 'id_user' parameters to the specified endpoint, thereby retrieving data belonging to other users. This could lead to data breaches and compromise the privacy of individuals using this application.
Affected Version(s)
CanalDenuncia.app 0 < 4.4.8
