CVE-2025-31997Medium· 4.2▾ SunlitHCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
unica_centralized_offer_management < 25.1.0.1Upgrade past the affected range:
unica_centralized_offer_management 25.1.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-31993Low· 3.5HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF)
CVE-2025-31998Low· 3.5HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information
CVE-2025-12288Medium· 4.3A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4
CVE-2025-12283Medium· 4.3A security flaw has been discovered in code-projects Client Details System 1.0
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)