CVE-2023-43900
⚪ Do wiadomości
Nieautoryzowany dostęp do danych w EMSigner umożliwia manipulacja parametrami documentID i EncryptedDocumentId.
CVSS
6.5
EPSS
0.6%
Exploit
poc
Vendor
emudhra
Opis źródłowy (NVD)
Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2023-11-14 05:15:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-27 16:57:55 UTC |
Referencje
- https://secpro.llc/emsigner-cve-3/ (cve@mitre.org) [Exploit, Third Party Advisory]