Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0.
The vulnerability results from improper storage of sensitive data in cookies without encryption (CWE-312, CWE-315). An attacker can exploit this flaw to manipulate the communication protocol (Protocol Manipulation) or conduct a JSON Hijacking attack (JavaScript Hijacking), which involves intercepting JSON responses returned by the application. Data in cookies is available in plain text, which facilitates its reading and modification by unauthorized entities.
An attacker can intercept sensitive information from cookies, including session or authentication data, and then use it to gain unauthorized access to the application or its resources. It is also possible to manipulate data transmitted between the client and server.
The ValeApp application should be updated to version v2.0.0 or later, in which the issue has been eliminated. Detailed information is available in the vendor's references and in the USOM security bulletin (TR-24-1562).
Oceanic Software ValeApp in all versions prior to v2.0.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOceanicsoft Valeapp
APPOceanicsoft< 2.0.0
Related vulnerabilities
Session Fixation w Oceanicsoft ValeApp umożliwia przejęcie sesji
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic ...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in O...
Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System...