CVE-2023-43900
בינונית 6.5
תיאור (מקור, אנגלית)
Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-8/10/2026
- CWE
- CWE-639
מוצרים מושפעים
emudhra: emsigner
קישורים
- https://secpro.llc/emsigner-cve-3/ ExploitThird Party Advisory
- https://secpro.llc/emsigner-cve-3/ ExploitThird Party Advisory
- https://secpro.co/blog/cve-2023-43900