CanalDenuncia.app Lack of Authorization Vulnerability Allowing Unauthorized Access to User Information
Vulnerability
A lack of authorization vulnerability exists in CanalDenuncia.app versions prior to 4.4.8. This vulnerability enables attackers to access information belonging to other users by sending a POST request with specific parameters, 'id_denuncia' and 'seguro', to the endpoint '/backend/api/buscarUsuarioByDenuncia.php'.
Impact
Exploitation of this vulnerability allows unauthorized users to access sensitive information of other users, potentially leading to privacy violations or misuse of that information.
Remediation
Users can update to CanalDenuncia.app version 4.4.8 to address this vulnerability.
Added: Nov 4, 2025, 2:20 PM
Updated: Nov 4, 2025, 3:45 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
7.7relevance
0.9threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
