CWE-598
Use of HTTP Request With Sensitive Query String
Description
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (92)
page 3 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-8997 | Med | 0.37 | — | 0.00 | Aug 25, 2025 | An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited. | ||
| CVE-2024-12012 | — | Med | 0.37 | 5.7 | 0.00 | Feb 13, 2025 | A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to… | |
| CVE-2024-32931 | Med | 0.37 | 5.7 | 0.00 | Aug 1, 2024 | Under certain circumstances the exacqVision Web Service can expose authentication token details within communications. | ||
| CVE-2025-54542 | Med | 0.36 | 5.5 | 0.00 | Aug 28, 2025 | QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of… | ||
| CVE-2025-51651 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2025 | An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request. | ||
| CVE-2023-22307 | Med | 0.36 | 5.5 | 0.00 | Apr 18, 2023 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files. | ||
| CVE-2025-31954 | Med | 0.35 | 5.4 | 0.00 | Nov 5, 2025 | HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were… | ||
| CVE-2026-37504 | Med | 0.34 | 5.3 | 0.00 | May 1, 2026 | Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /api/v1/server/UniProxy/user?token=SECRET,… | ||
| CVE-2026-31381 | Med | 0.34 | 5.3 | 0.00 | Mar 20, 2026 | An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL. | ||
| CVE-2026-22644 | Med | 0.34 | 5.3 | 0.00 | Jan 15, 2026 | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access. | ||
| CVE-2025-58584 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed… | ||
| CVE-2025-40742 | Med | 0.34 | 5.3 | 0.00 | Jul 8, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V11.0), SIPROTEC 5… | ||
| CVE-2025-49188 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering. | ||
| CVE-2026-47768 | Med | 0.29 | 5.5 | 0.00 | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2. | ||
| CVE-2025-32916 | Med | 0.28 | 4.3 | 0.00 | Oct 9, 2025 | Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places such as browser history or web… | ||
| CVE-2025-50709 | Med | 0.28 | 4.3 | 0.00 | Sep 17, 2025 | An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter | ||
| CVE-2024-9877 | Med | 0.28 | 4.3 | 0.00 | Apr 30, 2025 | : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4. | ||
| CVE-2023-50954 | Med | 0.28 | 4.3 | 0.00 | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776. | ||
| CVE-2017-9280 | Med | 0.28 | 4.3 | 0.01 | Mar 2, 2018 | Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar. | ||
| CVE-2026-26196 | Med | 0.27 | 5.3 | 0.00 | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2. |
- risk 0.37cvss —epss 0.00
An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.
- risk 0.37cvss 5.7epss 0.00
A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to…
- risk 0.37cvss 5.7epss 0.00
Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
- risk 0.36cvss 5.5epss 0.00
QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of…
- risk 0.36cvss 5.5epss 0.00
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.
- risk 0.36cvss 5.5epss 0.00
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
- risk 0.35cvss 5.4epss 0.00
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…
- risk 0.34cvss 5.3epss 0.00
Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /api/v1/server/UniProxy/user?token=SECRET,…
- risk 0.34cvss 5.3epss 0.00
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
- risk 0.34cvss 5.3epss 0.00
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.
- risk 0.34cvss 5.3epss 0.00
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed…
- risk 0.34cvss 5.3epss 0.00
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V11.0), SIPROTEC 5…
- risk 0.34cvss 5.3epss 0.00
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
- risk 0.29cvss 5.5epss 0.00
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.
- risk 0.28cvss 4.3epss 0.00
Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places such as browser history or web…
- risk 0.28cvss 4.3epss 0.00
An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
- risk 0.28cvss 4.3epss 0.00
: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.
- risk 0.28cvss 4.3epss 0.00
IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.
- risk 0.28cvss 4.3epss 0.01
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.
- risk 0.27cvss 5.3epss 0.00
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2.