Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://hackerone.com/reports/2580062 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2024-07-12T15:41:03.461Z
Updated: 2024-08-02T03:50:56.177Z
Reserved: 2024-06-08T01:04:07.093Z
Link: CVE-2024-37405
Vulnrichment
Updated: 2024-07-15T15:07:23.883Z
NVD
Status : Awaiting Analysis
Published: 2024-07-12T16:15:03.207
Modified: 2024-11-21T09:23:47.573
Link: CVE-2024-37405
Redhat
No data.