CVE-2025-41099: Insecure Direct Object Reference in GPS BOLD Workplanner
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the list of permissions using unauthorised internal identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41099?
The severity of CVE-2025-41099 is high due to the potential for unauthorized access to sensitive permissions.
How do I fix CVE-2025-41099?
To fix CVE-2025-41099, upgrade BOLD Workplanner to version 2.5.25 or higher to ensure adequate validation of user inputs.
Who is affected by CVE-2025-41099?
Authenticated users of BOLD Workplanner versions prior to 2.5.25 are affected by CVE-2025-41099.
What type of vulnerability is CVE-2025-41099?
CVE-2025-41099 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What can an attacker do with CVE-2025-41099?
An attacker exploiting CVE-2025-41099 can access lists of permissions using unauthorized internal identifiers.