CVE-2025-41096: Insecure Direct Object Reference in GPS BOLD Workplanner
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41096?
CVE-2025-41096 has been classified with a high severity due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2025-41096?
To fix CVE-2025-41096, upgrade BOLD Workplanner to version 2.5.25 or later, which includes the necessary security patches.
What type of vulnerability is CVE-2025-41096?
CVE-2025-41096 is an Insecure Direct Object Reference (IDOR) vulnerability.
Who is impacted by CVE-2025-41096?
Authenticated users of BOLD Workplanner versions prior to 2.5.25 are at risk from CVE-2025-41096.
What does CVE-2025-41096 allow unauthorized users to do?
CVE-2025-41096 allows unauthorized users to access the dates of current contract details, leading to potential data exposure.