CNNVD-202510-368 Information
Oct 02, 2025
cve
CNNVD ID
CNNVD-202510-368
Related CVE
- CNNVD Published: 2025-10-02
Description (Chinese)
ViDay是西班牙ViDay公司的一个业务管理平台。 ViDay存在跨站脚本漏洞,该漏洞源于HTTP请求中JWT包含敏感用户信息,可能导致信息泄露。
Description (English)
ViDay is a business management platform for ViDay in Spain. ViDay had a cross-site script loophole, which stemmed from the fact that JWT contained sensitive user information in the HTTP request, which could lead to disclosure.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
ViDay
Published
2025-10-02
Last Modified
2026-02-24
References
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-energy-crm-status-tracker https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-viday https://access.redhat.com/security/cve/cve-2025-40646
Share on: