Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: DIVD
Published: 2022-06-08T00:00:00Z
Updated: 2024-09-17T04:29:42.554Z
Reserved: 2022-02-14T00:00:00
Link: CVE-2022-25151
Vulnrichment
Updated: 2024-08-03T04:29:01.856Z
NVD
Status : Modified
Published: 2022-06-09T17:15:08.787
Modified: 2024-11-21T06:51:42.090
Link: CVE-2022-25151
Redhat
No data.