GHSA-93xg-c6hj-rp82HighCVSS 7.5

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.

🔗 References (3)