Back

HIGH

Insecure Direct Object Reference en Deporsite de T-INNOVA

Published Apr 15, 2025

Description

Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" endpoint.

Affected products

Remediation

Vendor solution

The vulnerabilities have been fixed by the T-INNOVA team in release 2024.02 (DSuite2024 v06.1287 fix2). T-Innova has identified the customers using the affected module, and has applied the corresponding patch.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCIBE
Published Apr 15, 2025
Updated Apr 15, 2025
Reserved Apr 14, 2025

CISA Vulnrichment

Updated Apr 15, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCIBE
Published Apr 15, 2025
Updated Apr 15, 2025

GitHub

No data