CVE-2025-41093: Insecure Direct Object Reference in GPS BOLD Workplanner
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41093?
CVE-2025-41093 is classified as a medium severity vulnerability due to potential unauthorized access to sensitive contract details.
How do I fix CVE-2025-41093?
To fix CVE-2025-41093, update BOLD Workplanner to version 2.5.25 or later, which addresses the IDOR issues.
What type of vulnerability is CVE-2025-41093?
CVE-2025-41093 is an Insecure Direct Object Reference (IDOR) vulnerability.
Who is affected by CVE-2025-41093?
Users of BOLD Workplanner versions prior to 2.5.25 are affected by CVE-2025-41093.
What is the impact of CVE-2025-41093?
The impact of CVE-2025-41093 includes unauthorized access to basic contract details through insufficient validation of user input.