Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Oct 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload. | |
Title | Exposure of sensitive information in Viday | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-02T09:42:30.375Z
Reserved: 2025-04-16T08:38:12.620Z
Link: CVE-2025-40646

No data.

Status : Received
Published: 2025-10-02T10:15:38.140
Modified: 2025-10-02T10:15:38.140
Link: CVE-2025-40646

No data.

No data.