The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://cert.pl/en/posts/2024/01/CVE-2023-49253/ | third party advisory |
https://cert.pl/posts/2024/01/CVE-2023-49253/ | third party advisory |