ZeroHour

CVE-2022-45895

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

Vendors
planetestream
Products
planet estream
Weakness
CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.