# N/A
### 概述
Envasadora H2O Eireli - Soda Cristal v40.20.4 存在不安全的直接对象引用(IDOR)漏洞。
### 影响版本
- **版本**:v40.20.4
### 细节
该漏洞允许经过认证的攻击者通过构造特定的 HTTP 请求,访问其他用户的敏感数据。
### 影响
- **攻击条件**:需要用户已认证(登录)。
- **攻击后果**:未经授权访问其他用户的敏感信息。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via a crafted HTTP request. | https://github.com/milamrk/CVE-2025-52389 | POC详情 |
| 2 | An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows unauthenticated attackers to access sensitive data for other users via a crafted HTTP request. | https://github.com/ktr4ck3r/CVE-2025-52389 | POC详情 |
标题: GitHub - ktr4ck3r/CVE-2025-52389: An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows unauthenticated attackers to access sensitive data for other users via a crafted HTTP request. -- 🔗来源链接
标签:
神龙速读暂无评论