CVE-2025-41010
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-02

Last updated on: 2025-10-02

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description
Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in a controlled manner. This request has an β€œOrigin” header that identifies the domain making the initial request and defines the protocol between a browser and a server to see if the request is allowed. An attacker can exploit this and potentially perform privileged actions and access confidential information when Access-Control-Allow-Credentials is enabled.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-02
Last Modified
2025-10-02
Generated
2026-05-07
AI Q&A
2025-10-02
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hiberus sintra *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-942 The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. CORS is a security feature that controls how browsers make requests across different domains. The issue arises when the server improperly handles the 'Origin' header and allows cross-domain requests with credentials enabled, which can let an attacker perform privileged actions or access confidential information.


How can this vulnerability impact me? :

If exploited, this vulnerability can allow an attacker to perform privileged actions on behalf of a user and access confidential information by bypassing normal cross-origin restrictions, potentially leading to unauthorized data access or manipulation.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart