4.3
CVE-2014-1930
- EPSS 0.83%
- Veröffentlicht 10.02.2014 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Visibility Software ≫ Cyber Recruiter Version <= 8.0
Visibility Software ≫ Cyber Recruiter Version6.2
Visibility Software ≫ Cyber Recruiter Version6.4
Visibility Software ≫ Cyber Recruiter Version6.6
Visibility Software ≫ Cyber Recruiter Version6.8
Visibility Software ≫ Cyber Recruiter Version7.0
Visibility Software ≫ Cyber Recruiter Version7.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.83% | 0.737 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.