SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-40646

Exposure of sensitive information in Viday.

MEDIUM 5.9EPSS 0.18%

Does this matter?

Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.

Description

Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.

CVSS 4.0
5.9 MEDIUMCVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.18% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
energycrm/energy crm
Source
cve-coordination@incibe.es

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.