Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-639 | |
Metrics |
cvssV3_1
|
Fri, 20 Dec 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers. | |
Title | Path Traversal and IDOR Vulnerabilities in eSignaViewer Allow Unauthorized File Access | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2024-12-20T12:58:02.961Z
Updated: 2024-12-20T15:48:58.229Z
Reserved: 2024-12-02T10:39:36.887Z
Link: CVE-2024-12014
Vulnrichment
Updated: 2024-12-20T15:48:53.047Z
NVD
Status : Received
Published: 2024-12-20T13:15:19.430
Modified: 2024-12-20T16:15:23.030
Link: CVE-2024-12014
Redhat
No data.