---
id: CVE-2025-40646
title: Exposure of sensitive information in Viday
summary: >-
  Exposure of sensitive information in Viday. This vulnerability could allow an
  attacker to obtain sensitive information about customers by intercepting HTTP
  requests and searching for the JWT containing sensitive user information in
  the J…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-200
vendor: energycrm
product: energy_crm
affected:
  - energy_crm = 2025
published: '2025-10-02'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40646'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-viday
    label: cve-coordination@incibe.es
tags:
  - nvd
epss: 0.00175
epssPercentile: 0.07324
ingestedAt: '2026-07-15T14:44:07.634Z'
---

## Overview

Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.

## Affected

- `energy_crm = 2025`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
