Insecure Direct Object Reference on Deporsite by T-INNOVA
Vulnerability Description
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3574
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Carlos Alonso Arranz
Affected Vendor
T-INNOVA
View all reports →