Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4v5-j466-v6ph

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

EPSS

Процентиль: 39%
0.00176
Низкий

Связанные уязвимости

CVSS3: 5.9
nvd
около 5 лет назад

In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

EPSS

Процентиль: 39%
0.00176
Низкий