Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Fixes

Solution

Users should immediately upgrade to the corresponding fixed version to eliminate these vulnerabilities and protect sensitive data from unauthorized access.


Workaround

No workaround given by the vendor.

History

Thu, 15 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 12:00:00 +0000

Type Values Removed Values Added
Description Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Title Insecure Direct Object Reference (IDOR) vulnerability in eSignaViewer
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Edgewatch

Published:

Updated: 2025-05-15T13:28:18.267Z

Reserved: 2025-05-15T11:45:21.855Z

Link: CVE-2025-4762

cve-icon Vulnrichment

Updated: 2025-05-15T13:27:16.048Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-15T12:15:23.560

Modified: 2025-05-16T14:43:26.160

Link: CVE-2025-4762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.