An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Insecure Direct Object Reference (IDOR) vulnerability, which occurs due to a lack of proper authorization checks when accessing objects referenced by this parameter. This allows direct access to other users' data or internal resources without proper permission. Successful exploitation of this flaw may result in the exposure of sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
System Pdv Project
System Pdv Project system Pdv |
|
CPEs | cpe:2.3:a:system_pdv_project:system_pdv:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
System Pdv Project
System Pdv Project system Pdv |
Mon, 25 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-639 | |
Metrics |
cvssV3_1
|
Mon, 25 Aug 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Insecure Direct Object Reference (IDOR) vulnerability, which occurs due to a lack of proper authorization checks when accessing objects referenced by this parameter. This allows direct access to other users' data or internal resources without proper permission. Successful exploitation of this flaw may result in the exposure of sensitive information. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-25T14:02:40.289Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-45968

Updated: 2025-08-25T14:01:57.332Z

Status : Analyzed
Published: 2025-08-25T14:15:31.210
Modified: 2025-10-21T13:51:24.520
Link: CVE-2025-45968

No data.

No data.