5.9
CVE-2025-40646
- EPSS 0.16%
- Veröffentlicht 02.10.2025 10:15:38
- Zuletzt bearbeitet 15.07.2026 14:17:03
- CVE-Watchlists
- Unerledigt
Multiple vulnerabilities in Energy CRM by Status Tracker
Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Energycrm ≫ Energy Crm Version2025
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.059 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| cve-coordination@incibe.es | 5.9 | 0 | 0 |
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-viday