Home
LOW: 2.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:NDefault status
affected
1.3.2
unaffected
1.4.4
unaffected
4.0.4
unaffected
4.1.4
unaffected
5.0.2
unaffected
5.1.2
unaffected
5.2.4
unaffected
5.3.3
unaffected
5.4.1
unaffected
Description
Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Problem types
CWE-20: Improper Input Validation
Product status
1.3.2
1.4.4
4.0.4
4.1.4
5.0.2
5.1.2
5.2.4
5.3.3
5.4.1
Credits
Pablo Alcarria Lozano
References
edgewatch.com/...signaviewer-allow-unauthorized-file-access/