CVE-2025-41358: Cronosweb i2a Cronosweb

High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.

Affected products

Published 2025-12-10. Last modified 2026-09-25.