Lleidanet eSigna IDOR Vulnerability in eSignaViewer Component Allows Unauthorized File Access
Vulnerability
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in the eSignaViewer component of the eSigna product, affecting versions 1.0 to 1.5 on all platforms. This vulnerability allows an unauthenticated attacker to access arbitrary files in the document system by manipulating file paths and object identifiers. The issue arises from insufficient authorization checks on user-controlled references, such as document IDs, enabling unauthorized access to sensitive files.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive data, potentially causing regulatory violations.
Remediation
Users are advised to upgrade to eSignaViewer versions 1.3.2, 1.4.4, 4.0.4, 4.1.4, 5.0.2, 5.1.2, 5.2.4, 5.3.3, or 5.4.1.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
