Executive brief
Vimesoft Corporate Messaging Platform, a tool used for internal business communications, contains a vulnerability that may inadvertently expose sensitive information. An attacker could potentially retrieve private data that was unintentionally embedded in communications sent through the platform. This could lead to the unauthorized disclosure of confidential corporate information or user details.
Technical details
A vulnerability classified as CWE-201 (Insertion of Sensitive Information Into Sent Data) exists in the Vimesoft Corporate Messaging Platform. The flaw allows for the retrieval of embedded sensitive data from information sent by the application. The attack vector is network-based with high complexity, requiring no prior authentication but necessitating some form of user interaction. An attacker successfully exploiting this could gain access to confidential information that the application failed to strip before transmission. The issue affects versions starting from V1.3.0 and is fixed in version V2.0.0.
Affected products
- Vimesoft Information Technologies and Software Inc. Corporate Messaging Platform V1.3.0 to V2.0.0 (exclusive)
Timeline
- 2025-09-26: disclosed
- 2025-09-26: advisory