High severity7.5NVD Advisory· Published Nov 4, 2025· Updated Jun 17, 2026
CVE-2025-41335
CVE-2025-41335
Description
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:canaldenuncia:canaldenuncia.app:*:*:*:*:*:*:*:*range: <4.4.8
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-canaldenunciaappnvdThird Party Advisory
News mentions
0No linked articles in our index yet.