Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
all versions
affected
Description
Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensitive information about customers by sending an HTTP GET request to “/api/reserva/web/clients” using the “phone” parameter.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
all versions
Credits
Carolina Gómez Uriarte
Gema de la Fuente Romero
References
www.incibe.es/...otices/aviso/multiple-vulnerabilities-viday