Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Viday
Viday viday |
|
Vendors & Products |
Viday
Viday viday |
Thu, 02 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 02 Oct 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload. | |
Title | Exposure of sensitive information in Viday | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-10-02T09:42:30.375Z
Updated: 2025-10-02T17:29:04.291Z
Reserved: 2025-04-16T08:38:12.620Z
Link: CVE-2025-40646

Updated: 2025-10-02T17:28:58.267Z

Status : Awaiting Analysis
Published: 2025-10-02T10:15:38.140
Modified: 2025-10-02T19:11:46.753
Link: CVE-2025-40646

No data.