In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSick Baggage Analytics
APPSickall versionsSick Enterprise Analytics
APPSickall versionsSick Logistic Diagnostic Analytics
APPSickall versionsSick Package Analytics
APPSickall versionsSick Tire Analytics
APPSickall versions
Related vulnerabilities
Obejście uwierzytelniania w SICK Package Analytics przez REST API
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default pe...
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint...
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient va...