Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-549m-hv69-px2r

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

EPSS

Процентиль: 74%
0.00825
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 12 лет назад

Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

EPSS

Процентиль: 74%
0.00825
Низкий

Дефекты

CWE-200