A Missing Authorization vulnerability has been found in DinoRANK. This
vulnerability allows an attacker to access invoices of any user via
accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there
is no access control. The pdf filename can be obtained via OSINT,
insecure network traffic or brute force.
CVSS
No CVSS.
References
Configurations
No configuration.
History
28 May 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-28 11:15
Updated : 2025-05-28 15:01
NVD link : CVE-2025-40673
Mitre link : CVE-2025-40673
CVE.ORG link : CVE-2025-40673
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization