Junglewise Threat Intelligence

CVE-2025-40646: ViDay sensitive information exposure in JWT payload

CVE-2025-40646 · Severity: medium · CVSS 5.4 · Published 2025-10-02

Executive brief

ViDay, a booking and business management application, contains a security flaw that exposes sensitive customer data. An attacker who is able to intercept network traffic can view private user information stored within security tokens (JWTs) used by the app. This could lead to the unauthorized disclosure of personal customer details and potentially impact the privacy and reputation of businesses using the platform.

Technical details

An information exposure vulnerability (CWE-200) exists in the ViDay booking application due to the inclusion of sensitive user information within the payload of JSON Web Tokens (JWT). The vulnerability is triggered when an attacker intercepts HTTP requests containing these tokens. Because JWT payloads are typically Base64-encoded and not encrypted, any party capable of intercepting the traffic (such as an attacker on an adjacent network or via a man-in-the-middle position) can decode the token to obtain private customer data. The vulnerability affects all versions of the software, and no official patch has been reported at this time.

Affected products

  • ViDay ViDay All versions

Timeline

  • 2025-10-02: advisory: Initial advisory published by INCIBE-CERT

References