CVE-2025-41030: T-Innova Deporsite
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain information from other users via GET ‘/ajax/TInnova_v2/Integrantes_Recurso_v2_1/llamadaAjax/buscarPersona’ using the ‘dni’ parameter.
Affected products
- T-Innova Deporsite: before v02.14.1115 (fixed in v02.14.1115)
Published 2025-09-02. Last modified 2026-06-17.