---
id: CVE-2023-43900
title: >-
  Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to
  gain unauthorized access to application content and view sensitive data of
  other users via manipulation of the documentID and EncryptedDocumentId
  parameters.
summary: >-
  Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to
  gain unauthorized access to application content and view sensitive data of
  other users via manipulation of the documentID and EncryptedDocumentId
  parameters.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: emudhra
product: emsigner
affected:
  - emsigner = 2.8.7
published: '2023-11-14'
updated: '2026-08-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-43900'
references:
  - url: 'https://secpro.llc/emsigner-cve-3/'
    label: cve@mitre.org
  - url: 'https://secpro.llc/emsigner-cve-3/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00593
epssPercentile: 0.46075
ingestedAt: '2026-08-27T17:05:15.879Z'
---

## Overview

Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.

## Affected

- `emsigner = 2.8.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
