CVE-2025-3405 | FCJ Venture Builder appclientefiel 3.0.27 HTTP GET Request ObterPedido ORDER_ID resource injection
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/cliente/ObterPedido/ of the component HTTP GET Request Handler. The manipulation of the argument ORDER_ID leads to improper control of resource identifiers.
This vulnerability is known as CVE-2025-3405. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.