Metrics
Affected Vendors & Products
Mon, 03 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Energycrm
Energycrm energy Crm |
|
| CPEs | cpe:2.3:a:energycrm:energy_crm:2025:*:*:*:*:*:*:* | |
| Vendors & Products |
Energycrm
Energycrm energy Crm |
|
| Metrics |
cvssV3_1
|
Fri, 10 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| References |
|
Fri, 10 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload. | Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to “/crm/create_job_submit.php”, using the “JobCreatedBy” parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details. |
| Title | Exposure of sensitive information in Viday | Multiple vulnerabilities in Energy CRM by Status Tracker |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Viday
Viday viday |
|
| Vendors & Products |
Viday
Viday viday |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload. | |
| Title | Exposure of sensitive information in Viday | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-10-02T09:42:30.375Z
Updated: 2025-10-10T08:20:22.420Z
Reserved: 2025-04-16T08:38:12.620Z
Link: CVE-2025-40646
Updated: 2025-10-02T17:28:58.267Z
Status : Analyzed
Published: 2025-10-02T10:15:38.140
Modified: 2025-11-03T15:15:59.487
Link: CVE-2025-40646
No data.