Back

MEDIUM

Broken access control vulnerability in the Innovación y Cualificación IcProgreso plugin

Published Mar 17, 2025

Description

Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more.

Affected products

Remediation

Vendor solution

Innovación y Cualificación has released a new version that fixes the vulnerabilities detected in the affected plugins. It has been implemented in all installations of the affected software, and the process will be completed in December 2024.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Mar 17, 2025
Updated Mar 17, 2025
Reserved Mar 11, 2025
CISA Vulnrichment
Updated Mar 17, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a