ZeroHour

CVE-2020-13129

CVSS 3.1
7.2 high
EPSS
2%p76
Published
()
Modified
Description

An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string, which allows attackers to obtain sensitive information by reading web-server logs.

Vendors
heinekingmedia
Products
stashcat
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.