CVE-2025-41030: T-Innova Deporsite

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain information from other users via GET ‘/ajax/TInnova_v2/Integrantes_Recurso_v2_1/llamadaAjax/buscarPersona’ using the ‘dni’ parameter.

Affected products

  • T-Innova Deporsite: before v02.14.1115 (fixed in v02.14.1115)

Published 2025-09-02. Last modified 2026-06-17.