Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h59v-x7wr-gq9p

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers are only those with a password-protected scan workflow connector. This issue affects Y Soft SafeQ 6 in versions before MU106.

Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers are only those with a password-protected scan workflow connector. This issue affects Y Soft SafeQ 6 in versions before MU106.

EPSS

Процентиль: 13%
0.00044
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-549

Связанные уязвимости

nvd
25 дней назад

Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers are only those with a password-protected scan workflow connector. This issue affects Y Soft SafeQ 6 in versions before MU106.

EPSS

Процентиль: 13%
0.00044
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-549