Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgpq-gf6r-4vr6

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.

EPSS

Процентиль: 82%
0.01712
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-200
CWE-598

Связанные уязвимости

CVSS3: 9.8
nvd
около 8 лет назад

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.

EPSS

Процентиль: 82%
0.01712
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-200
CWE-598