Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5w8-77gv-454j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either remotely compromises or obtains physical access to a user's workstation can browse the browser cache contents and obtain sensitive information. The attacker does not need to be authenticated with the application to view this information, as it would be available via the browser cache.

An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either remotely compromises or obtains physical access to a user's workstation can browse the browser cache contents and obtain sensitive information. The attacker does not need to be authenticated with the application to view this information, as it would be available via the browser cache.

EPSS

Процентиль: 63%
0.00458
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either remotely compromises or obtains physical access to a user's workstation can browse the browser cache contents and obtain sensitive information. The attacker does not need to be authenticated with the application to view this information, as it would be available via the browser cache.

CVSS3: 7.5
debian
почти 6 лет назад

An issue was discovered in Zammad 3.0 through 3.2. It does not prevent ...

EPSS

Процентиль: 63%
0.00458
Низкий