Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8g3-5fhj-q8xr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.

The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.

EPSS

Процентиль: 86%
0.0285
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 15 лет назад

The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.

nvd
около 15 лет назад

The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.

debian
около 15 лет назад

The autocompletion functionality in GLPI before 0.80.2 does not blackl ...

EPSS

Процентиль: 86%
0.0285
Низкий

Дефекты

CWE-200