Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.
History

Thu, 19 Sep 2024 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published: 2022-06-08T00:00:00Z

Updated: 2024-09-17T04:29:42.554Z

Reserved: 2022-02-14T00:00:00

Link: CVE-2022-25151

cve-icon Vulnrichment

Updated: 2024-08-03T04:29:01.856Z

cve-icon NVD

Status : Analyzed

Published: 2022-06-09T17:15:08.787

Modified: 2023-06-23T18:57:58.710

Link: CVE-2022-25151

cve-icon Redhat

No data.