Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwq8-5gf7-6jfp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

EPSS

Процентиль: 67%
0.0056
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 13 лет назад

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

EPSS

Процентиль: 67%
0.0056
Низкий

Дефекты

CWE-200