CVE-2025-41069EPSS p14.6%
CVE-2025-41069CVE-2025-41069
Description
Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorized resources by manipulating requests using the 'idUsuario' parameter in ‘/ajax/TInnova_v2/Formulario_Consentimiento/llamadaAjax/obtenerDatosConsentimientos’, which could lead to the exposure or alteration os confidential data.
Scoring
| EPSS | 0.25% probability of exploitation · percentile 14.6% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |