CVE-2025-40659: Acc Dm Corporative CMS
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.
Affected products
- Acc Dm Corporative CMS: before 2025.01 (fixed in 2025.01)
Published 2025-06-10. Last modified 2026-06-17.