Lleidanet eSigna IDOR Vulnerability in eSignaViewer Component Allows Unauthorized File Access

Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability has been identified in the eSignaViewer component of the eSigna product, affecting versions 1.0 to 1.5 on all platforms. This vulnerability allows an unauthenticated attacker to access arbitrary files in the document system by manipulating file paths and object identifiers. The issue arises from insufficient authorization checks on user-controlled references, such as document IDs, enabling unauthorized access to sensitive files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive data, potentially causing regulatory violations.

Remediation

Users are advised to upgrade to eSignaViewer versions 1.3.2, 1.4.4, 4.0.4, 4.1.4, 5.0.2, 5.1.2, 5.2.4, 5.3.3, or 5.4.1.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.