GN4 Publishing System Insecure Direct Object Reference (IDOR) Information Disclosure
Published Oct 24, 2025
8.6
HIGHCVSS 4.0
EPSS 0.42%
Description
GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints allow an authenticated user to request arbitrary user IDs and receive sensitive account data for those users, including the stored password and the account's security question and answer. The exposed recovery data and encrypted password may be used to reset or take over the target account.
Affected products
-
Affected
- ≥ 0, < 2.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Naviga Global / Miles 33 | GN4 Publishing System | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-35899 Advisory
- https://nne.navigacloud.com/GN4Help/gn4_introduction_to_gn4.htm product
- https://www.miles33.com/news/news/5955/naviga--miles-33--acquisition.html media-coveragerelated
- https://www.miles33.com/section/14/gn4 product
- https://www.vulncheck.com/advisories/gn4-publishing-system-idor-information-disclosure third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-35899 | Advisory | |
| https://nne.navigacloud.com/GN4Help/gn4_introduction_to_gn4.htm | product | |
| https://www.miles33.com/news/news/5955/naviga--miles-33--acquisition.html | media-coveragerelated | |
| https://www.miles33.com/section/14/gn4 | product | |
| https://www.vulncheck.com/advisories/gn4-publishing-system-idor-information-disclosure | third-party-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data