CVE-2025-3405
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-3405 is a newly identified vulnerability affecting the FCJ Venture Builder appclientefiel version 3.0.27. This issue lies within the HTTP GET Request Handler component and the affected functionality is currently unknown. Manipulation of the ORDER_ID argument in the /rest/cliente/ObterPedido/ file allows an attacker to exert unintended control over resource identifiers, leading to potential security risks. This vulnerability can be exploited remotely, and the exploit has been publicly disclosed, increasing the threat level. Unfortunately, the vendor has not responded to early notifications about this disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.