Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmwg-qm4w-3cmq

Опубликовано: 14 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. These emails are sent without using an encrypted transmission protocol. If an attacker intercepts the packets, they can obtain the plaintext session information and use it to log into the system.

The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. These emails are sent without using an encrypted transmission protocol. If an attacker intercepts the packets, they can obtain the plaintext session information and use it to log into the system.

8.8 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

nvd
больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

8.8 High

CVSS3

Дефекты

CWE-319