Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
History

Thu, 15 May 2025 12:00:00 +0000

Type Values Removed Values Added
Description Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers. Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Title Path Traversal and IDOR Vulnerabilities in eSignaViewer Allow Unauthorized File Access Path Traversal vulnerability in eSignaViewer Allow Unauthorized File Access

Fri, 20 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Dec 2024 13:15:00 +0000

Type Values Removed Values Added
Description Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Title Path Traversal and IDOR Vulnerabilities in eSignaViewer Allow Unauthorized File Access
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-12-20T12:58:02.961Z

Updated: 2025-05-15T11:42:33.751Z

Reserved: 2024-12-02T10:39:36.887Z

Link: CVE-2024-12014

cve-icon Vulnrichment

Updated: 2024-12-20T15:48:53.047Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-20T13:15:19.430

Modified: 2025-05-15T12:15:22.047

Link: CVE-2024-12014

cve-icon Redhat

No data.