5.9
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.
Basic Information
ID
CVE-2025-40646
Source
INCIBE
Published
Oct 2, 2025 at 09:42
Affected Product
Vendor
ViDay
Product
ViDay
Version
all versions
Affected Versions
ViDay ViDay all versions