CVE-2023-43900
Executive Summary
CVE-2023-43900: In eMudhra emSigner v2.8.7, authenticated users can exploit an insecure direct object reference vulnerability by manipulating the documentID and EncryptedDocumentId parameters, enabling unauthorized access to other users’ documents and sensitive data. The flaw allows data exposure without requiring elevated privileges. The vulnerability is not yet listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2023-11-14T05:15:08.700 - Last Modified: 2026-08-28T16:16:49.307
Original Description: Insecure Direct Object References (IDOR) in eMudhra emSigner v2.8.7 allow authenticated attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.
"A life spent making mistakes is not only more honourable but more useful than a life spent in doing nothing."
— Bernard Shaw