CVE-2025-41020
16.10.2025, 08:15
Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sergestec | exito | 8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration