CVE-2025-41094: Insecure Direct Object Reference in GPS BOLD Workplanner
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to functional contract details using unauthorised internal identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41094?
CVE-2025-41094 is considered a critical vulnerability due to its potential to allow unauthorized access to sensitive contract details.
How do I fix CVE-2025-41094?
To fix CVE-2025-41094, upgrade BOLD Workplanner to version 2.5.25 or later, which includes patches for this vulnerability.
What versions of BOLD Workplanner are affected by CVE-2025-41094?
BOLD Workplanner versions prior to 2.5.25 are affected by CVE-2025-41094.
Who can exploit CVE-2025-41094?
CVE-2025-41094 can be exploited by authenticated users who lack proper authorization to access specific contract details.
What type of vulnerability is CVE-2025-41094?
CVE-2025-41094 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.