CVE-2025-41097: Insecure Direct Object Reference in GPS BOLD Workplanner
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic employee details using unauthorised internal identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41097?
CVE-2025-41097 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive employee details.
How do I fix CVE-2025-41097?
To fix CVE-2025-41097, upgrade your BOLD Workplanner to version 2.5.25 or later, which addresses the insecure direct object reference issue.
Who is affected by CVE-2025-41097?
Any organization using BOLD Workplanner versions prior to 2.5.25 is affected by CVE-2025-41097.
What type of vulnerability is CVE-2025-41097?
CVE-2025-41097 is an Insecure Direct Object Reference (IDOR) vulnerability.
What can an attacker do with CVE-2025-41097?
An attacker could exploit CVE-2025-41097 to gain unauthorized access to basic employee details by manipulating internal identifiers.