4.3
CVE-2014-1930
- EPSS 1.53%
- Veröffentlicht 10.02.2014 22:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Visibility Software ≫ Cyber Recruiter Version <= 8.0
Visibility Software ≫ Cyber Recruiter Version6.2
Visibility Software ≫ Cyber Recruiter Version6.4
Visibility Software ≫ Cyber Recruiter Version6.6
Visibility Software ≫ Cyber Recruiter Version6.8
Visibility Software ≫ Cyber Recruiter Version7.0
Visibility Software ≫ Cyber Recruiter Version7.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.53% | 0.714 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://jvn.jp/vu/JVNVU97441356/index.html
http://osvdb.org/102814
http://osvdb.org/102815
http://www.kb.cert.org/vuls/id/566894
http://www.securityfocus.com/bid/65305
http://www.vspublic.com/help/Cyber%20Recruiter/default.aspx?pageid=release_details