← Back

Emudhra

emudhra

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Emsigner
emsigner

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Emsigner
Emudhra
2Emsigner
Emsigner
Aug 28, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a cr...Show more
Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.Show less
2Emsigner
Emudhra
2Emsigner
Emsigner
Aug 28, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.
2Emsigner
Emudhra
2Emsigner
Emsigner
Aug 28, 2026
Nov 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the document...Show more
Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.Show less