CVE-2023-43900

Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.
References
Link Resource
https://secpro.llc/emsigner-cve-3/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:emsigner:emsigner:2.8.7:*:*:*:*:*:*:*

History

17 Nov 2023, 19:36

Type Values Removed Values Added
CPE cpe:2.3:a:emsigner:emsigner:2.8.7:*:*:*:*:*:*:*
CWE CWE-639
References () https://secpro.llc/emsigner-cve-3/ - () https://secpro.llc/emsigner-cve-3/ - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Emsigner
Emsigner emsigner

14 Nov 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-14 05:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-43900

Mitre link : CVE-2023-43900

CVE.ORG link : CVE-2023-43900


JSON object : View

Products Affected

emsigner

  • emsigner
CWE
CWE-639

Authorization Bypass Through User-Controlled Key