PT-2025-40330 · Viday · Viday

Andrea Intilangelo

·

Published

2025-10-02

·

Updated

2025-10-10

·

CVE-2025-40646

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Viday (affected versions not specified)
Description The software exhibits a flaw that could allow an attacker to obtain sensitive customer information. This is achieved by intercepting HTTP requests and locating JWTs within the request payload. The JWTs contain sensitive user information, potentially exposing it to unauthorized access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-40646

Affected Products

Viday