Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of documents.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-viafirma-products | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-01-12 15:16
Updated : 2026-01-29 20:12
NVD link : CVE-2025-41078
Mitre link : CVE-2025-41078
CVE.ORG link : CVE-2025-41078
JSON object : View
Products Affected
viafirma
- documents
- documents_compose
CWE
CWE-863
Incorrect Authorization
