CVE-2025-41031: T-Innova Deporsite

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other users' profile pictures via a POST request using the parameters ‘IdPersona’ and “Foto” in ‘/ajax/TInnova_c/FotoUsuario/llamadaAjax/uploadImage’.

Affected products

  • T-Innova Deporsite: before v02.14.1115 (fixed in v02.14.1115)

Published 2025-09-02. Last modified 2026-06-17.