CVE-2025-40646
⚪ Do wiadomości
Ujawnienie wrażliwych informacji w Viday umożliwia atakującemu pozyskanie danych klientów.
CVSS
5.4
EPSS
0.2%
Exploit
none
Vendor
energycrm
Opis źródłowy (NVD)
Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-10-02 10:15:38 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |