Insecure Direct Object Reference in GPS BOLD Workplanner
Vulnerability Description
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to calendar details using unauthorised internal identifiers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41091
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Ángel González
More from GLOBAL PLANNING SOLUTIONS S.L (GPS)
View All →Affected Vendor
GLOBAL PLANNING SOLUTIONS S.L (GPS)
View all reports →