ViDay Sensitive Information Exposure Vulnerability
Vulnerability
A vulnerability allowing unauthenticated attackers to access sensitive customer information has been identified in the ViDay booking application. This issue arises from the application's API, specifically the 'clients' endpoint, which can be accessed by sending an HTTP GET request with the 'phone' parameter. The vulnerability is present in all versions of ViDay.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive customer information.
Added: Oct 2, 2025, 10:24 AM
Updated: Oct 2, 2025, 10:24 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
0.0relevance
0.6threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
