5
CVE-2014-0999
- EPSS 6.65%
- Veröffentlicht 02.06.2015 14:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.65% | 0.93 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://packetstormsecurity.com/files/132022/Sendio-ESP-Information-Disclosure.html
http://seclists.org/fulldisclosure/2015/May/95
http://www.exploit-db.com/exploits/37114
http://www.securityfocus.com/archive/1/535592/100/0/threaded
http://www.sendio.com/software-release-history/