Vulnerability CVE-2022-45895


Published: 2022-12-25

Description:
Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Planet eStream Code Execution / SQL Injection / XSS / Broken Control
Philipp Espernbe...
09.12.2022

 References:
https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-planet-enterprises-ltd-planet-estream/

Copyright 2024, cxsecurity.com

 

Back to Top