Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
No solution has been reported at this time.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hiberus
Hiberus sintra |
|
| Vendors & Products |
Hiberus
Hiberus sintra |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in a controlled manner. This request has an “Origin” header that identifies the domain making the initial request and defines the protocol between a browser and a server to see if the request is allowed. An attacker can exploit this and potentially perform privileged actions and access confidential information when Access-Control-Allow-Credentials is enabled. | |
| Title | Cross-origin resource sharing (CORS) in Hiberus Sintra | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-02T15:52:28.607Z
Reserved: 2025-04-16T09:08:43.217Z
Link: CVE-2025-41010
Updated: 2025-10-02T15:18:19.050Z
Status : Deferred
Published: 2025-10-02T13:15:31.717
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41010
No data.
OpenCVE Enrichment
Updated: 2025-10-03T08:22:44Z