CVE-2025-41092: Insecure Direct Object Reference in GPS BOLD Workplanner
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to time records details using unauthorised internal identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41092?
CVE-2025-41092 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive time records.
How do I fix CVE-2025-41092?
To fix CVE-2025-41092, upgrade BOLD Workplanner to version 2.5.25 or later, which includes necessary input validation measures.
What are the risks associated with CVE-2025-41092?
The risks of CVE-2025-41092 include unauthorized access to sensitive data, which can lead to data breaches and privacy violations.
Who is affected by CVE-2025-41092?
CVE-2025-41092 affects users of BOLD Workplanner versions prior to 2.5.25.
What type of vulnerability is CVE-2025-41092?
CVE-2025-41092 is an Insecure Direct Object Reference (IDOR) vulnerability resulting from insufficient validation of user inputs.