CVE-2025-41020 - Sergestec Exito
Critical 7.5
Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.
Affected software
Sergestec Exito