VYPR

CWE-598

Use of HTTP Request With Sensitive Query String

VariantDraft

Description

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (99)

page 5 of 5
  • CVE-2023-6287LowNov 27, 2023
    risk 0.21cvss 3.3epss 0.00

    Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.

  • CVE-2025-14808LowMar 25, 2026
    risk 0.20cvss 3.1epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

  • CVE-2025-14811LowMar 13, 2026
    risk 0.20cvss 3.1epss 0.00

    IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

  • CVE-2026-10078LowMay 29, 2026
    risk 0.18cvss 2.7epss 0.00

    A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL query parameters during POST requests to the GitLab endpoint. This insecure…

  • CVE-2022-34452LowFeb 10, 2023
    risk 0.18cvss 2.7epss 0.00

    PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs.

  • CVE-2025-62317LowMay 14, 2026
    risk 0.17cvss 2.6epss 0.00

    HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain…

  • CVE-2024-28238LowMar 12, 2024
    risk 0.15cvss 2.3epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g., web server logs, browser…

  • CVE-2025-32021LowApr 15, 2025
    risk 0.14cvss 2.2epss 0.00

    Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for…

  • CVE-2025-3637LowApr 25, 2025
    risk 0.13cvss 3.1epss 0.00

    A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and…

  • CVE-2023-45716LowFeb 9, 2024
    risk 0.11cvss 1.7epss 0.00

    Sametime is impacted by sensitive information passed in URL.

  • CVE-2026-27949LowApr 7, 2026
    risk 0.06cvss 2.0epss 0.00

    Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted).…

  • CVE-2026-16207LowJul 19, 2026
    risk 0.00cvss 3.7epss 0.01

    A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The attack can be launched remotely. This…

  • CVE-2026-15322HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.01

    IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.

  • CVE-2026-9592HigJul 17, 2026
    risk 0.00cvss —epss 0.00

    SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.

  • CVE-2026-62386HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server…

  • CVE-2026-54652HigJul 8, 2026
    risk 0.00cvss 8.1epss 0.00

    Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request…

  • CVE-2026-58656HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious website. Attackers who obtain…

  • CVE-2026-23846HigJan 19, 2026
    risk 0.00cvss 8.1epss 0.00

    Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs…

  • CVE-2025-57800HigAug 22, 2025
    risk 0.00cvss 8.8epss 0.00

    Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshelf to store an arbitrary…