PT-2025-16357 · Joturl · Joturl
CVE-2025-24948
·
Publicado
2025-04-15
·
Atualizado
2025-04-22
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JotUrl version 2.0
Description
The issue involves passwords being sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.
Recommendations
For JotUrl version 2.0, consider disabling the use of HTTP GET-type requests for password transmission until a secure method is implemented. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using insecure protocols for transmitting sensitive information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Joturl