CVEbaza.plSłownik CWECWE-598
Common Weakness Enumeration

CWE-598

Use of HTTP Request With Sensitive Query String

Kategoria: VariantCVE: 92
Opis

Aplikacja internetowa wykorzystuje metodę HTTP do przetwarzania żądania, ale żądanie zawiera wrażliwe informacje w ciągu zapytania. Może to prowadzić do ujawnienia poufnych danych w logach serwera, historii przeglądarki lub podczas przesyłania żądania.

Description (EN)

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Podatności CVE z CWE-598 (92)
9.8
CVSS
CRITICAL
CVE-2023-6014

Podatność w MLflow umożliwia atakującemu utworzenie dowolnego konta użytkownika bez spełnienia jakichkolwiek wymagań uwierzytelnienia. Jest to krytyczna luka, ponieważ pozwala nieuprawnionej osobie uzyskać dostęp do systemu z pominięciem mechanizmów kontroli dostępu.

pub. 2023-11-16
9.8
CVSS
CRITICAL
CVE-2018-14822

W urządzeniach Entes EMG12 w wersjach 2.57 i wcześniejszych zidentyfikowano podatność polegającą na ujawnianiu wrażliwych danych (np. danych uwierzytelniających) poprzez ciągi zapytań (query strings) w interfejsie webowym. Podatność ta może umożliwić atakującemu podszycie się pod legalnego użytkownika i wykonanie dowolnego kodu.

pub. 2018-10-02
9.8
CVSS
CRITICAL
CVE-2017-3185

Kamery ACTi serii D, B, I i E z firmware A1D-500-V6.11.31-AC przesyłają nazwę użytkownika i hasło jako parametry metody GET zamiast POST, co naraża te dane na nieuprawnione ujawnienie. Podatność uzyskała ocenę krytyczną (CVSS 9.8), ponieważ nie wymaga żadnego uwierzytelnienia ani interakcji użytkownika po stronie atakującego.

pub. 2017-12-16
9.3
CVSS
CRITICAL
CVE-2026-76179

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.

pub. 2026-08-28
9.3
CVSS
CRITICAL
CVE-2026-74880

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.

pub. 2026-08-17
9.0
CVSS
CRITICAL
CVE-2025-69634

W Dolibarr ERP & CRM w wersji 22.0.9 odkryto podatność Cross-Site Request Forgery (CSRF) w pliku perms.php, która według zgłoszenia pozwala zdalnemu atakującemu na eskalację uprawnień. Podatność jest jednak kwestionowana przez stronę trzecią, która wskazuje, że skuteczna eksploitacja wymaga znajomości tokenu użytkownika administracyjnego przez nieuprzywilejowanego atakującego.

pub. 2026-02-12
8.8
CVSS
HIGH
CVE-2025-50110

An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS

pub. 2025-09-15
8.8
CVSS
HIGH
CVE-2025-57800

Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshelf to store an arbitrary callback in a cookie, which is later used to redirect the user after authentication. The server then issues a 302 redirect to the attacker-controlled URL, appending sensitive OIDC tokens as query parameters. This allows an attacker to obtain the victim's tokens and perform full account takeover, including creating persistent admin users if the victim is an administrator. Tokens are further leaked via browser history, Referer headers, and server logs. This vulnerability impacts all Audiobookshelf deployments using OIDC; no IdP misconfiguration is required. The issue is fixed in version 2.28.0. No known workarounds exist.

pub. 2025-08-22
8.8
CVSS
HIGH
CVE-2021-36328

Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.

pub. 2021-11-30
8.8
CVSS
HIGH
CVE-2020-5331

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks.

pub. 2020-05-04
8.8
CVSS
HIGH
CVE-2019-18573

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.

pub. 2019-12-18
8.7
CVSS
HIGH
CVE-2026-58656

Wtyczka Grav API przed wersją v1.0.0-rc.16 akceptuje tokeny JWT przekazywane jako parametr zapytania URL (?token=) i zwraca nagłówek Access-Control-Allow-Origin: *, co umożliwia nieuwierzytelnionym atakującym wykonywanie w pełni uwierzytelnionych żądań API cross-origin z dowolnej złośliwej strony. Podatność jest szczególnie groźna, ponieważ tokeny JWT mogą wyciekać przez logi dostępowe, logi proxy, historię przeglądarki lub nagłówki Referrer.

pub. 2026-07-08
8.7
CVSS
HIGH
CVE-2025-26473

The Mojave Inverter uses the GET method for sensitive information.

pub. 2025-02-13
8.3
CVSS
HIGH
CVE-2022-22551

DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.

pub. 2022-01-21
8.2
CVSS
HIGH
CVE-2026-62386

Wtyczka Grav API (getgrav/grav-plugin-api) w wersjach przed 1.0.0-rc.16 akceptuje tokeny JWT przez parametr URL `?token=`, co powoduje ich utrwalenie w logach serwera, historii przeglądarki i nagłówkach Referer. Wyciek tokenu umożliwia nieuprawniony dostęp do API z uprawnieniami administratora.

pub. 2026-07-17
8.2
CVSS
HIGH
CVE-2025-56551

An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.

pub. 2025-10-03
8.2
CVSS
HIGH
CVE-2024-31206

dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily intercepted and modified by attackers. Anyone who uses the package could be the victim of a man-in-the-middle (MITM) attack. The network request was upgraded to HTTPS in version `1.0.1`. There are no workarounds, but some precautions include not sending any sensitive information and carefully verifying the API response before saving it.

pub. 2024-04-04
8.2
CVSS
HIGH
CVE-2021-21594

Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.

pub. 2021-08-16
8.1
CVSS
HIGH
CVE-2026-54652

W aplikacji Frigate (open source network video recorder) w wersji 0.17.1 każdy uwierzytelniony użytkownik, w tym posiadający jedynie rolę viewer, może pobrać logi systemowe zawierające automatycznie generowane hasła administratora oraz dane uwierzytelniające kamer. Umożliwia to nieuprawnione przejęcie uprawnień administracyjnych (privilege escalation).

pub. 2026-07-08
8.1
CVSS
HIGH
CVE-2026-23846

Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs and potentially exposed through browser history, Referer headers, and proxy logs. Version 1.16.1 patches the issue.

pub. 2026-01-19
Pokazano 20 z 92 podatności
Informacje
ID: CWE-598
Typ: Variant
Podatności: 92
MITRE CWE ↗
← Słownik CWE