CVE-2025-41031
02.09.2025, 09:15
Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other users' profile pictures via a POST request using the parameters IdPersona and Foto in /ajax/TInnova_c/FotoUsuario/llamadaAjax/uploadImage.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.