CVE-2025-41358: Cronosweb i2a Cronosweb
High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.
Affected products
- Cronosweb i2a Cronosweb
Published 2025-12-10. Last modified 2026-09-25.