VYPR
Medium severityNVD Advisory· Published May 28, 2025· Updated Apr 15, 2026

CVE-2025-40673

CVE-2025-40673

Description

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing authorization vulnerability in DinoRANK allows any unprivileged user to access other users' invoices via predictable PDF URLs.

Vulnerability

Overview

A missing authorization vulnerability (CWE-862) has been identified in DinoRANK, a SEO tool. The bug lies in the endpoint /facturas/YYYY-MM/SDRYYMM-XXXXX.pdf, which lacks any access control checks. This allows an attacker to retrieve invoice PDFs belonging to any user of the platform without authentication or privileged access [1].

Exploitation & Attack Surface

The attack is straightforward: the attacker simply visits the predictable URL pattern for an invoice. The filename structure (e.g., SDRYYMM-XXXXX.pdf) is partially guessable, and the full path can be obtained through OSINT, insecure network traffic sniffing, or brute-force enumeration [1]. No special privileges are required, and the attack can be executed remotely over the network (CVSS AV:N/AC:L/PR:L/UI:N). The CVSS v4.0 base score is 5.3 (Medium) with a vector of AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N [1].

Impact

An attacker who successfully guesses or discovers a valid invoice URL gains access to sensitive financial data of other users, including invoice details. This constitutes a confidentiality breach, as the vulnerability exposes user invoices to unauthorized parties. The impact does not extend to integrity or availability [1].

Mitigation

The vulnerability has been fixed by the DinoRANK team in the latest version. Users should update their DinoRANK installations to the most recent release to protect against this issue [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.