CVE-2023-43900

Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.
References
Link Resource
https://secpro.llc/emsigner-cve-3/ Exploit Third Party Advisory
https://secpro.llc/emsigner-cve-3/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:emsigner:emsigner:2.8.7:*:*:*:*:*:*:*

History

21 Nov 2024, 08:24

Type Values Removed Values Added
References () https://secpro.llc/emsigner-cve-3/ - Exploit, Third Party Advisory () https://secpro.llc/emsigner-cve-3/ - Exploit, Third Party Advisory

17 Nov 2023, 19:36

Type Values Removed Values Added
First Time Emsigner
Emsigner emsigner
CPE cpe:2.3:a:emsigner:emsigner:2.8.7:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-639
References () https://secpro.llc/emsigner-cve-3/ - () https://secpro.llc/emsigner-cve-3/ - Exploit, Third Party Advisory

Information

Published : 2023-11-14 05:15

Updated : 2024-11-21 08:24


NVD link : CVE-2023-43900

Mitre link : CVE-2023-43900

CVE.ORG link : CVE-2023-43900


JSON object : View

Products Affected

emsigner

  • emsigner
CWE
CWE-639

Authorization Bypass Through User-Controlled Key