Логотип exploitDog
bind:CVE-2020-7932
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-7932

Количество 2

Количество 2

nvd логотип

CVE-2020-7932

больше 5 лет назад

OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-vwxv-frj6-fhc9

больше 3 лет назад

OMERO-web Sensitive Data Exposure

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-7932

OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.

CVSS3: 5.7
0%
Низкий
больше 5 лет назад
github логотип
GHSA-vwxv-frj6-fhc9

OMERO-web Sensitive Data Exposure

CVSS3: 5.7
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу