An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows unauthenticated attackers to access sensitive data for other users via a crafted HTTP request.
# CVE-2025-52389
# Description
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows unauthenticated attackers to access sensitive data for other users via a crafted HTTP request.
# Version
app.sodacristal - 40.20.4
## Proof of Concept
When accessing the customer's contract at https://www.app.sodacristal.com/contrato/#contract_number# you can change the number so you can see another customer's contract.
To make the filter easier you can use burp suite and filter by site length.
登录后查看神龙缓存的 POC 文件快照
登录查看