TROYANOSYVIRUS
Back to CVEs

CVE-2025-41078

HIGH
8.1

Description

Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of documents.

CVE Details

CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published1/12/2026
Last Modified1/29/2026
Sourcenvd
Honeypot Sightings0

Affected Products

viafirma:documentsviafirma:documents_compose

Weaknesses (CWE)

CWE-863

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.