CVE-2024-12014
Severity CVSS v4.0:
LOW
Type:
CWE-20
Input Validation
Publication date:
20/12/2024
Last modified:
20/12/2024
Description
Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
7.50
Severity 3.x
HIGH