CVE-2025-69752
Deferred Deferred - Pending Action

Insecure Direct Object Reference in Ideagen Q-Pulse

Vulnerability report for CVE-2025-69752, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-12

Last updated on: 2026-07-05

Assigner: MITRE

Description

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-12
Last Modified
2026-07-05
Generated
2026-07-26
AI Q&A
2026-02-12
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ideagen q-pulse 7.1.0.32

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the "My Details" user profile functionality of Ideagen Q-Pulse version 7.1.0.32. It allows an authenticated user to access other users' profile information by modifying the objectKey HTTP parameter in the URL of the My Details page.

Detection Guidance

I don't know

Impact Analysis

The vulnerability can lead to unauthorized disclosure of personal or sensitive user profile information within the Ideagen Q-Pulse system. An authenticated user could view details of other users without proper permission, potentially leading to privacy breaches or misuse of information.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-69752. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart