Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
History

Fri, 20 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Dec 2024 13:15:00 +0000

Type Values Removed Values Added
Description Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Title Path Traversal and IDOR Vulnerabilities in eSignaViewer Allow Unauthorized File Access
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-12-20T12:58:02.961Z

Updated: 2024-12-20T15:48:58.229Z

Reserved: 2024-12-02T10:39:36.887Z

Link: CVE-2024-12014

cve-icon Vulnrichment

Updated: 2024-12-20T15:48:53.047Z

cve-icon NVD

Status : Received

Published: 2024-12-20T13:15:19.430

Modified: 2024-12-20T16:15:23.030

Link: CVE-2024-12014

cve-icon Redhat

No data.