PT-2018-14565 · Prayer · Prayer

Matthew Vernon

·

Publicado

2018-10-26

·

Atualizado

2018-10-30

·

CVE-2018-18655

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Prayer versions 1.0 through 1.3.5
Description The issue arises when a user clicks on a link in their email, causing Prayer to send a Referer header that contains the user's username. This occurs because the header.t lacks a no-referrer setting.
Recommendations For versions 1.0 through 1.3.5, consider adding a no-referrer setting to the header.t to prevent the inclusion of the username in the Referer header.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18655

Produtos afetados

Prayer