CVE-2025-41092
30.09.2025, 11:37
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user toaccess to time records details using unauthorised internal identifiers.Enginsight
| Vendor | Product | Version |
|---|---|---|
| boldworkplanner | bold_workplanner | 𝑥 < 2.5.25 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration