Back

MEDIUM

Missing Authorization in DinoRANK

Published May 28, 2025

Description

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by DinoRANK team in the latest version.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published May 28, 2025
Updated May 28, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated May 28, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published May 28, 2025
Updated May 28, 2025
Exploited since n/a
EUVD-2025-16323