CVE-2022-45895

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).
Configurations

Configuration 1 (hide)

cpe:2.3:a:planetestream:planet_estream:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
References () https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-planet-enterprises-ltd-planet-estream/ - Exploit, Third Party Advisory () https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-planet-enterprises-ltd-planet-estream/ - Exploit, Third Party Advisory

Information

Published : 2022-12-25 05:15

Updated : 2024-11-21 07:29


NVD link : CVE-2022-45895

Mitre link : CVE-2022-45895

CVE.ORG link : CVE-2022-45895


JSON object : View

Products Affected

planetestream

  • planet_estream
CWE
CWE-668

Exposure of Resource to Wrong Sphere