CVE-2025-41358EPSS p24.8%
CVE-2025-41358CVE-2025-41358
Description
Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.
Scoring
| EPSS | 0.34% probability of exploitation · percentile 24.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-25 |