VYPR

CWE-598

Use of HTTP Request With Sensitive Query String

VariantDraft

Description

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (92)

page 3 of 5
  • CVE-2025-8997MedAug 25, 2025
    risk 0.37cvss epss 0.00

    An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

  • CVE-2024-12012MedFeb 13, 2025
    risk 0.37cvss 5.7epss 0.00

    A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to…

  • CVE-2024-32931MedAug 1, 2024
    risk 0.37cvss 5.7epss 0.00

    Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

  • CVE-2025-54542MedAug 28, 2025
    risk 0.36cvss 5.5epss 0.00

    QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of…

  • CVE-2025-51651MedJul 14, 2025
    risk 0.36cvss 5.5epss 0.00

    An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

  • CVE-2023-22307MedApr 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.

  • CVE-2025-31954MedNov 5, 2025
    risk 0.35cvss 5.4epss 0.00

    HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were…

  • CVE-2026-37504MedMay 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /api/v1/server/UniProxy/user?token=SECRET,…

  • CVE-2026-31381MedMar 20, 2026
    risk 0.34cvss 5.3epss 0.00

    An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.

  • CVE-2026-22644MedJan 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.

  • CVE-2025-58584MedOct 6, 2025
    risk 0.34cvss 5.3epss 0.00

    In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed…

  • CVE-2025-40742MedJul 8, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V11.0), SIPROTEC 5…

  • CVE-2025-49188MedJun 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

  • CVE-2026-47768MedJul 28, 2026
    risk 0.29cvss 5.5epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.

  • CVE-2025-32916MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places such as browser history or web…

  • CVE-2025-50709MedSep 17, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter

  • CVE-2024-9877MedApr 30, 2025
    risk 0.28cvss 4.3epss 0.00

    : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

  • CVE-2023-50954MedJun 30, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.

  • CVE-2017-9280MedMar 2, 2018
    risk 0.28cvss 4.3epss 0.01

    Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.

  • CVE-2026-26196MedMar 5, 2026
    risk 0.27cvss 5.3epss 0.00

    Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2.