Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the Dmacroweb team in version 2025.01.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17649 | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/select node/data.asp?mode=catalogue&id1=1&id2=1session=&cod=1&networks=0. |
Wed, 22 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acc
Acc dm Corporative Cms |
|
| CPEs | cpe:2.3:a:acc:dm_corporative_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Acc
Acc dm Corporative Cms |
|
| Metrics |
cvssV3_1
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/select node/data.asp?mode=catalogue&id1=1&id2=1session=&cod=1&networks=0. | |
| Title | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-06-10T14:04:26.591Z
Reserved: 2025-04-16T08:38:13.919Z
Link: CVE-2025-40660
Updated: 2025-06-10T14:04:07.216Z
Status : Analyzed
Published: 2025-06-10T10:15:28.627
Modified: 2025-10-22T13:53:05.590
Link: CVE-2025-40660
No data.
OpenCVE Enrichment
No data.
EUVD