VYPR

CWE-598

Use of HTTP Request With Sensitive Query String

VariantDraft

Description

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (99)

page 4 of 5
  • CVE-2026-88897MedSep 10, 2026
    risk 0.31cvss 5.9epss 0.00

    Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.

  • CVE-2026-61614MedSep 4, 2026
    risk 0.31cvss 5.9epss 0.00

    SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs,…

  • CVE-2026-47768MedJul 28, 2026
    risk 0.29cvss 5.5epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2.

  • CVE-2025-32916MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places such as browser history or web…

  • CVE-2025-50709MedSep 17, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter

  • CVE-2024-9877MedApr 30, 2025
    risk 0.28cvss 4.3epss 0.00

    : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

  • CVE-2023-50954MedJun 30, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.

  • CVE-2017-9280MedMar 2, 2018
    risk 0.28cvss 4.3epss 0.01

    Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.

  • CVE-2026-55375MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing access logs, proxy logs, and APM traces to…

  • CVE-2026-26196MedMar 5, 2026
    risk 0.27cvss 5.3epss 0.00

    Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2.

  • CVE-2025-3943MedMay 22, 2025
    risk 0.27cvss 4.1epss 0.10

    Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1,…

  • CVE-2025-26058MedFeb 18, 2025
    risk 0.27cvss 4.2epss 0.00

    Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.

  • CVE-2023-25524MedAug 3, 2023
    risk 0.26cvss 4.0epss 0.00

    NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources.…

  • CVE-2025-2356LowMar 17, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API Handler. The manipulation leads to use of get request method with sensitive query strings. It is possible to initiate the…

  • CVE-2025-0730LowJan 27, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP GET Request Handler. The manipulation of the argument username/password leads to…

  • CVE-2023-32335LowMar 13, 2024
    risk 0.24cvss 3.7epss 0.01

    IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM…

  • CVE-2023-50328LowFeb 2, 2024
    risk 0.24cvss 3.7epss 0.01

    IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.

  • CVE-2025-52901MedJun 30, 2025
    risk 0.22cvss 4.5epss 0.01

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is used as a session identifier…

  • CVE-2026-33620MedMar 26, 2026
    risk 0.21cvss 4.3epss 0.00

    PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` through `v0.8.3` accepted the API token from a `token` URL query parameter in addition to the `Authorization` header. When a valid API credential is sent in the URL,…

  • CVE-2024-2745LowApr 2, 2024
    risk 0.21cvss 3.3epss 0.00

    Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to…