CVE-2025-41358 - CVE House
Back to Database
Status published High CVE-2025-41358

Direct reference to insecure objects (IDOR) in CronosWeb from CronosWeb i2A

Vulnerability Description

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41358

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Félix Sánchez Medina

Affected Vendor

CronosWeb i2A

View all reports →

Affected Software

CronosWeb
Vulnerable Versions:
25.00 and 24.05.

Timeline

Official Publish: December 10th, 2025
Last Modified: December 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)