All the vulnerabilites related to GLOBAL PLANNING SOLUTIONS S.L (GPS) - BOLD Workplanner
cve-2025-41099
Vulnerability from cvelistv5
Published
2025-09-30 11:17
Modified
2025-09-30 19:24
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41099", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:23:54.026465Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:24:03.057Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to the list of permissions using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to the list of permissions using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:17:30.044Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41099", "datePublished": "2025-09-30T11:17:30.044Z", "dateReserved": "2025-04-16T09:09:37.997Z", "dateUpdated": "2025-09-30T19:24:03.057Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41093
Vulnerability from cvelistv5
Published
2025-09-30 11:13
Modified
2025-09-30 19:22
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41093", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:22:30.097376Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:22:52.080Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to\u0026nbsp;basic contract details using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to\u00a0basic contract details using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:13:48.555Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41093", "datePublished": "2025-09-30T11:13:48.555Z", "dateReserved": "2025-04-16T09:09:36.724Z", "dateUpdated": "2025-09-30T19:22:52.080Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41094
Vulnerability from cvelistv5
Published
2025-09-30 11:14
Modified
2025-09-30 19:24
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41094", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:23:59.180578Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:24:40.970Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to functional\u0026nbsp;contract details using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to functional\u00a0contract details using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:14:33.108Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41094", "datePublished": "2025-09-30T11:14:33.108Z", "dateReserved": "2025-04-16T09:09:36.725Z", "dateUpdated": "2025-09-30T19:24:40.970Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41095
Vulnerability from cvelistv5
Published
2025-09-30 11:15
Modified
2025-09-30 19:25
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41095", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:25:09.458148Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:25:16.750Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to planning counter details using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to planning counter details using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:15:55.509Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41095", "datePublished": "2025-09-30T11:15:55.509Z", "dateReserved": "2025-04-16T09:09:37.996Z", "dateUpdated": "2025-09-30T19:25:16.750Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41098
Vulnerability from cvelistv5
Published
2025-09-30 11:18
Modified
2025-09-30 19:23
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41098", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:23:21.181573Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:23:33.563Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\u003cdiv\u003eInsecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a\u0026nbsp; misuse of the general enquiry web service.\u003cbr\u003e\u003c/div\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a\u00a0 misuse of the general enquiry web service." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:18:20.965Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41098", "datePublished": "2025-09-30T11:18:20.965Z", "dateReserved": "2025-04-16T09:09:37.996Z", "dateUpdated": "2025-09-30T19:23:33.563Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41092
Vulnerability from cvelistv5
Published
2025-09-30 11:12
Modified
2025-09-30 19:21
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41092", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:19:51.735498Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:21:12.468Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to time records details using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to time records details using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:12:59.221Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41092", "datePublished": "2025-09-30T11:12:59.221Z", "dateReserved": "2025-04-16T09:09:36.724Z", "dateUpdated": "2025-09-30T19:21:12.468Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41097
Vulnerability from cvelistv5
Published
2025-09-30 11:16
Modified
2025-09-30 19:24
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41097", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:24:22.565380Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:24:28.801Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to basic employee details using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to basic employee details using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:16:55.358Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41097", "datePublished": "2025-09-30T11:16:55.358Z", "dateReserved": "2025-04-16T09:09:37.996Z", "dateUpdated": "2025-09-30T19:24:28.801Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41096
Vulnerability from cvelistv5
Published
2025-09-30 11:16
Modified
2025-09-30 19:24
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41096", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:24:42.588079Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:24:49.948Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to the dates of the current contract details using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to the dates of the current contract details using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:16:31.984Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41096", "datePublished": "2025-09-30T11:16:31.984Z", "dateReserved": "2025-04-16T09:09:37.996Z", "dateUpdated": "2025-09-30T19:24:49.948Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41091
Vulnerability from cvelistv5
Published
2025-09-30 11:10
Modified
2025-09-30 19:18
Severity ?
EPSS score ?
Summary
Insecure Direct Object Reference in GPS BOLD Workplanner
References
Impacted products
▼ | Vendor | Product |
---|---|---|
GLOBAL PLANNING SOLUTIONS S.L (GPS) | BOLD Workplanner |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41091", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-09-30T19:18:08.337566Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-30T19:18:22.090Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "BOLD Workplanner", "vendor": "GLOBAL PLANNING SOLUTIONS S.L (GPS)", "versions": [ { "status": "affected", "version": "2.5.24" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "\u00c1ngel Gonz\u00e1lez" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (\u003ci\u003e4935b438f9b\u003c/i\u003e), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u0026nbsp;access to calendar details using unauthorised internal identifiers.\u003cbr\u003e" } ], "value": "Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to\u00a0access to calendar details using unauthorised internal identifiers." } ], "metrics": [ { "cvssV4_0": { "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "Safety": "NOT_DEFINED", "attackComplexity": "LOW", "attackRequirements": "NONE", "attackVector": "NETWORK", "baseScore": 7.1, "baseSeverity": "HIGH", "privilegesRequired": "LOW", "providerUrgency": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "userInteraction": "NONE", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N", "version": "4.0", "vulnAvailabilityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "NONE", "vulnerabilityResponseEffort": "NOT_DEFINED" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-639", "description": "CWE-639 Authorization Bypass Through User-Controlled Key", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-30T11:10:49.088Z", "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE" }, "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/insecure-direct-object-reference-gps-bold-workplanner" } ], "source": { "discovery": "UNKNOWN" }, "title": "Insecure Direct Object Reference in GPS BOLD Workplanner", "x_generator": { "engine": "Vulnogram 0.2.0" } } }, "cveMetadata": { "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "assignerShortName": "INCIBE", "cveId": "CVE-2025-41091", "datePublished": "2025-09-30T11:10:49.088Z", "dateReserved": "2025-04-16T09:09:36.724Z", "dateUpdated": "2025-09-30T19:18:22.090Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }