VYPR

CWE-598

Use of HTTP Request With Sensitive Query String

VariantDraft

Description

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (99)

page 3 of 5
  • CVE-2025-1738MedFeb 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity, exposing this sensitive information to a third party.

  • CVE-2025-13219MedMar 10, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.

  • CVE-2025-59873MedFeb 23, 2026
    risk 0.38cvss 5.9epss 0.00

    An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access to any network log or operates a site…

  • CVE-2024-41738MedNov 1, 2024
    risk 0.38cvss 5.9epss 0.00

    IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

  • CVE-2026-43875MedMay 11, 2026
    risk 0.37cvss 6.8epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=&pass= where is the victim's stored password hash…

  • CVE-2025-8997MedAug 25, 2025
    risk 0.37cvss —epss 0.00

    An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

  • CVE-2024-12012MedFeb 13, 2025
    risk 0.37cvss 5.7epss 0.00

    A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to…

  • CVE-2024-32931MedAug 1, 2024
    risk 0.37cvss 5.7epss 0.00

    Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

  • CVE-2026-82181MedAug 28, 2026
    risk 0.36cvss 5.5epss 0.00

    Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.

  • CVE-2025-54542MedAug 28, 2025
    risk 0.36cvss 5.5epss 0.00

    QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of…

  • CVE-2025-51651MedJul 14, 2025
    risk 0.36cvss 5.5epss 0.00

    An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

  • CVE-2023-22307MedApr 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.

  • CVE-2026-50157MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.01

    Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query…

  • CVE-2025-31954MedNov 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…

  • CVE-2026-37504MedMay 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /api/v1/server/UniProxy/user?token=SECRET,…

  • CVE-2026-31381MedMar 20, 2026
    risk 0.34cvss 5.3epss 0.00

    An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.

  • CVE-2026-22644MedJan 15, 2026
    risk 0.34cvss 5.3epss 0.01

    Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.

  • CVE-2025-58584MedOct 6, 2025
    risk 0.34cvss 5.3epss 0.00

    In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed…

  • CVE-2025-40742MedJul 8, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V11.0), SIPROTEC 5…

  • CVE-2025-49188MedJun 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.