CVE-2025-41358

HIGH

i2A CronosWeb <25.00.00.12 - IDOR

Title source: llm
STIX 2.1

Description

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.

Scores

CVSS v4 8.3
EPSS 0.0007
EPSS Percentile 22.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
CronosWeb i2A/CronosWeb 25.00 and 24.05.
Published Dec 10, 2025
Tracked Since Feb 18, 2026