Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Innovación y Cualificación has released a new version that fixes the vulnerabilities detected in the affected plugins. It has been implemented in all installations of the affected software, and the process will be completed in December 2024.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6601 | Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more. |
Mon, 17 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Mar 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php | Broken access control vulnerability in the Innovación y Cualificación IcProgreso plugin |
Mon, 17 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more. | |
| Title | Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-17T12:18:11.427Z
Reserved: 2025-03-11T09:52:09.599Z
Link: CVE-2025-2201
Updated: 2025-03-17T12:18:07.183Z
Status : Deferred
Published: 2025-03-17T10:15:16.543
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-2201
No data.
OpenCVE Enrichment
No data.
EUVD