CanalDenuncia.app Lack of Authorization Vulnerability Allowing Unauthorized Access to User Information

Vulnerability

A lack of authorization vulnerability exists in CanalDenuncia.app versions prior to 4.4.8. This vulnerability enables attackers to access information belonging to other users by sending a POST request with specific parameters. The issue arises in the '/backend/api/buscarTipoDenunciabyId.php' endpoint, where the 'id_tp_denuncia' and 'id_sociedad' parameters can be manipulated to retrieve unauthorized data.

Impact

Exploitation of this vulnerability allows for unauthorized access to other users' information within the CanalDenuncia.app platform.

Remediation

Users can update to CanalDenuncia.app version 4.4.8 to address this vulnerability.

Added: Nov 4, 2025, 2:21 PM
Updated: Nov 4, 2025, 3:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.