PT-2026-1494 · Sfwebservice · Inwave Jobs

CVE-2025-39477

·

Publicado

2026-01-06

·

Atualizado

2026-01-06

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InWave Jobs versions through 3.5.8
Description The Sfwebservice InWave Jobs software contains a missing authorization issue, allowing exploitation of incorrectly configured access control security levels. An unauthenticated attacker can execute privileged actions remotely.
Recommendations Update InWave Jobs to version 3.5.9.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-39477

Produtos afetados

Inwave Jobs