PT-2025-16357 · Joturl · Joturl
Published
2025-04-15
·
Updated
2025-04-22
·
CVE-2025-24948
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JotUrl version 2.0
Description
The issue involves passwords being sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.
Recommendations
For JotUrl version 2.0, consider disabling the use of HTTP GET-type requests for password transmission until a secure method is implemented. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using insecure protocols for transmitting sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joturl