Executive brief
ViDay, a booking and business management application, contains a security flaw that exposes sensitive customer data. An attacker who is able to intercept network traffic can view private user information stored within security tokens (JWTs) used by the app. This could lead to the unauthorized disclosure of personal customer details and potentially impact the privacy and reputation of businesses using the platform.
Technical details
An information exposure vulnerability (CWE-200) exists in the ViDay booking application due to the inclusion of sensitive user information within the payload of JSON Web Tokens (JWT). The vulnerability is triggered when an attacker intercepts HTTP requests containing these tokens. Because JWT payloads are typically Base64-encoded and not encrypted, any party capable of intercepting the traffic (such as an attacker on an adjacent network or via a man-in-the-middle position) can decode the token to obtain private customer data. The vulnerability affects all versions of the software, and no official patch has been reported at this time.
Affected products
- ViDay ViDay All versions
Timeline
- 2025-10-02: advisory: Initial advisory published by INCIBE-CERT